Vulnerabilities > CVE-2023-25012 - Use After Free vulnerability in Linux Kernel

047910
CVSS 4.6 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
low complexity
linux
CWE-416

Summary

The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.

Vulnerable Configurations

Part Description Count
OS
Linux
5306

Common Weakness Enumeration (CWE)