CVE-2023-53666

Description

A flaw was found in the Linux kernel's ASoC wcd938x codec component. This vulnerability stems from improper error handling during the initialization of the Multi-Band Headset Controller (MBHC). A local attacker with low privileges could exploit this by triggering a specific sequence of events, leading to an incorrect pointer dereference. This might result in a Denial of Service (DoS), corruption of system memory, or the disclosure of sensitive information.

Statement

This vulnerability does not affect RHEL 8, nor does it affect releases later than RHEL 9.3.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score75.5N/A
Attack VectorLocalLocalN/A
Attack ComplexityHighLowN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityHighNoneN/A
Integrity ImpactHighNoneN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Integrity,Other

Technical Impact: Varies by Context; Unexpected State

Errors that are not properly reported could place the system in an unexpected state that could lead to unintended behaviors.

Frequently Asked Questions

Want to get errata notifications? Sign up here.