{"id":"ASB-A-264029575", "published":"2023-04-01T00:00:00Z", "modified":"2026-05-01T15:24:27.653932157Z", "aliases":["CVE-2023-20941", "A-264029575"], "details":"In acc_ctrlrequest_composite of f_accessory.c, there is a possible out of bounds write due to a missing bounds check. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "affected":[{"package":{"name":":linux_kernel:", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":":0"}, {"fixed":":2023-04-05"}]}], "versions":["Kernel"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/kernel/common/+/f63204236560b6f38b6e015c53eb6304d9889791"], "severity":"High", "spl":"2023-04-05", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["154204816362201663845220166762614710976", "183086282322058050021166621569612086600", "232373756068662542242263383526850869792"], "threshold":0.9}, "id":"ASB-A-264029575-6d7ee53d", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/kernel/common/+/f63204236560b6f38b6e015c53eb6304d9889791", "target":{"file":"drivers/usb/gadget/function/f_accessory.c"}}, {"deprecated":false, "digest":{"line_hashes":["248582551586425433914416251034119873886", "242425980692480187201279409702591802556", "230543553597391539693556317969712070317", "322123129188396416488013275067709572730", "87280349668657444599006647142624594831", "182905368227727718570605089043184586092", "111398916614321270330149306316166323117", "167454371217771446201595815914141727578"], "threshold":0.9}, "id":"ASB-A-264029575-bab3c5b0", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/kernel/common/+/f63204236560b6f38b6e015c53eb6304d9889791", "target":{"file":"drivers/usb/gadget/configfs.c", "truncated_path_level":1}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2023-04-01"}, {"type":"FIX", "url":"https://android.googlesource.com/kernel/common/+/f63204236560b6f38b6e015c53eb6304d9889791"}]}