CVE-2023-25012 is a Use-After-Free vulnerability in the Linux kernel through version 6.1.9, specifically affecting the bigben_remove function in the HID Bigben Force Feedback driver. This flaw can be triggered by a crafted USB device due to LED controllers remaining registered for an excessive duration. With a CVSS score of 4.6 (Medium), exploitation requires physical access to the system (AV:P) and could lead to a denial of service (A:H). Currently, there is no public exploit code available, nor is there any evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.1.9CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-25012
Jun 11, 2024The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.
Feb 14, 2023kernel: hid: use-after-free in bigben_set_led()
Jan 25, 2023