LiveActive security incident?Get immediate response
CVE Record

CVE-2023-52477: usb: hub: Guard against accesses to uninitialized BOS descriptors

In the Linux kernel, the following vulnerability has been resolved: usb: hub: Guard against accesses to uninitialized BOS descriptors Many functions in drivers/usb/core/hub.c and drivers/usb/core/hub.h access fields inside udev->bos without checking if it was allocated and initialized. If usb_get_bos_descriptor() fails for whatever reason, udev->bos will be NULL and those accesses will result in a crash: BUG: kernel NULL pointer dereference, address: 0000000000000018 PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 5 PID: 17818 Comm: kworker/5:1 Tainted: G W 5.15.108-18910-gab0e1cb584e1 #1 <HASH:1f9e 1> Hardware name: Google Kindred/Kindred, BIOS Google_Kindred.12672.413.0 02/03/2021 Workqueue: usb_hub_wq hub_event RIP: 0010:hub_port_reset+0x193/0x788 Code: 89 f7 e8 20 f7 15 00 48 8b 43 08 80 b8 96 03 00 00 03 75 36 0f b7 88 92 03 00 00 81 f9 10 03 00 00 72 27 48 8b 80 a8 03 00 00 <48> 83 78 18 00 74 19 48 89 df 48 8b 75 b0 ba 02 00 00 00 4c 89 e9 RSP: 0018:ffffab740c53fcf8 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffffa1bc5f678000 RCX: 0000000000000310 RDX: fffffffffffffdff RSI: 0000000000000286 RDI: ffffa1be9655b840 RBP: ffffab740c53fd70 R08: 00001b7d5edaa20c R09: ffffffffb005e060 R10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000000 R13: ffffab740c53fd3e R14: 0000000000000032 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffffa1be96540000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000018 CR3: 000000022e80c005 CR4: 00000000003706e0 Call Trace: hub_event+0x73f/0x156e ? hub_activate+0x5b7/0x68f process_one_work+0x1a2/0x487 worker_thread+0x11a/0x288 kthread+0x13a/0x152 ? process_one_work+0x487/0x487 ? kthread_associate_blkcg+0x70/0x70 ret_from_fork+0x1f/0x30 Fall back to a default behavior if the BOS descriptor isn't accessible and skip all the functionalities that depend on it: LPM support checks, Super Speed capabilitiy checks, U1/U2 states setup.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2023-52477 is a Linux kernel USB hub flaw that can crash the kernel when USB BOS descriptor setup fails and later code assumes that data exists. The practical business concern is availability: affected systems may oops or reboot depending on configuration.

Executive priority

Treat as a patching and uptime risk, not a confirmed breach indicator. Prioritize servers, kiosks, endpoints, and appliances where USB access or device churn is plausible.

Technical view

Linux USB hub code in drivers/usb/core accessed udev->bos fields without confirming allocation after usb_get_bos_descriptor() failure. The fix adds guarded fallback behavior and skips BOS-dependent features, including LPM checks, SuperSpeed capability checks, and U1/U2 state setup.

Likely exposure

Exposure is most relevant to Linux systems running affected kernel versions with USB hub/device handling enabled. The provided sources do not establish network reachability or a remote attack path.

Exploitation context

The source describes a kernel NULL pointer dereference during USB hub workqueue processing after BOS descriptor retrieval fails. It does not cite public exploitation, weaponized proof of concept, or CISA KEV listing.

Researcher notes

Evidence supports a NULL pointer dereference when udev->bos is unavailable. The bundle lacks CVSS, CWE, exploitability analysis, and distribution-specific fixed package versions, so validation should rely on vendor kernel advisories and commit lineage.

Mitigation direction

  • Prioritize vendor kernel updates that include the referenced stable fixes.
  • Check distribution advisories for backported fixes matching your kernel package.
  • Limit untrusted physical USB device access where operationally feasible.
  • Monitor affected systems for kernel oops or crashes in USB hub paths.

Validation and detection

  • Inventory Linux kernel versions across systems with USB enabled.
  • Compare running kernels against vendor advisories and stable fix references.
  • Review kernel logs for hub_event or hub_port_reset NULL dereference traces.
  • Confirm patched kernels include guarded udev->bos access behavior.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-52477 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
9Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux0cdd49a1d1a483d80170d9e592f832274e8bce1b, 0cdd49a1d1a483d80170d9e592f832274e8bce1b, 0cdd49a1d1a483d80170d9e592f832274e8bce1b, 0cdd49a1d1a483d80170d9e592f832274e8bce1b, 0cdd49a1d1a483d80170d9e592f832274e8bce1b, 0cdd49a1d1a483d80170d9e592f832274e8bce1b, 0cdd49a1d1a483d80170d9e592f832274e8bce1b, 0cdd49a1d1a483d80170d9e592f832274e8bce1bunaffected
LinuxLinux4.6, 0, 4.14.328, 4.19.297, 5.4.259, 5.10.199, 5.15.136, 6.1.59, 6.5.8, 6.6affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.