Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52855

17
FAUCET Score

CVE-2023-52855 is a NULL pointer dereference vulnerability in the Linux kernel's USB DWC2 driver. It occurs due to a race condition between the enqueue and dequeue operations for USB Request Blocks (URBs), where urb->hcpriv can be set to NULL without proper locking, leading to a dereference. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and potentially leading to a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.2, < 4.14.330CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.299CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.261CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.201CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.139CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 68th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2023-52855Low

kernel: usb: dwc2: fix possible NULL pointer dereference caused by driver concurrency

May 21, 2024

References

git.kernel.org / stable/c/14c9ec34e8118fbffd7f5431814d767726323e72
Patch
git.kernel.org / stable/c/3e851a77a13ce944d703721793f49ee82622986d
Patch
git.kernel.org / stable/c/64c47749fc7507ed732e155c958253968c1d275e
Patch
git.kernel.org / stable/c/6b21a22728852d020a6658d39cd7bb7e14b07790
Patch
git.kernel.org / stable/c/a7bee9598afb38004841a41dd8fe68c1faff4e90
Patch
git.kernel.org / stable/c/bdb3dd4096302d6b87441fdc528439f171b04be6
Patch
git.kernel.org / stable/c/ef307bc6ef04e8c1ea843231db58e3afaafa9fa6
Patch
git.kernel.org / stable/c/fcaafb574fc88a52dce817f039f7ff2f9da38001
Patch
git.kernel.org / stable/c/fed492aa6493a91a77ebd51da6fb939c98d94a0d
Patch