Hide Forgot
A flaw was found in the Linux kernel. A use-after-free may be triggered in bigben_set_led() when plugging in a malicious USB device, which advertises itself as a bigben device. References: https://seclists.org/oss-sec/2023/q1/53 https://lore.kernel.org/all/20230125-hid-unregister-leds-v4-3-7860c5763c38@diag.uniroma1.it/ Upstream commit: https://github.com/torvalds/linux/commit/76ca8da989c7d97a7f76c75d475fe95a584439d7
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2172950]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-25012
This was fixed for Fedora with the 6.1.16 stable kernel updates.