CVE-2022-23467 is a medium-severity vulnerability affecting OpenRazer, an open-source driver for Razer devices on GNU/Linux. An attacker with a modified USB device can leak stack addresses, potentially bypassing Kernel Address Space Layout Randomization (KASLR). While no active exploitation or public exploit code exists, users are advised to upgrade to v3.5.1 and exercise caution with unknown USB devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.1CPE matchmatch criteria | cpe:2.3:a:openrazer_project:openrazer:*:*:*:*:*:linux:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.