In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
A bad USB device is able to construct a service connection response
message with target endpoint being ENDPOINT0 which is reserved for
HTC_CTRL_RSVD_SVC and should not be modified to be used for any other
services.
Reject such service connection responses.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-09-15 14:15
Updated : 2025-12-02 02:56
NVD link : CVE-2023-53185
Mitre link : CVE-2023-53185
CVE.ORG link : CVE-2023-53185
JSON object : View
Products Affected
linux
- linux_kernel
CWE
