{"schema_version":"1.7.5","id":"CVE-2023-37453","published":"2023-07-06T17:15:14.187Z","modified":"2026-03-15T22:47:04.785902Z","related":["ALSA-2024:2394","SUSE-SU-2023:3599-1","SUSE-SU-2023:3599-2","SUSE-SU-2023:3600-1","SUSE-SU-2023:3600-2","SUSE-SU-2023:3656-1","SUSE-SU-2023:3682-1","SUSE-SU-2023:3964-1","SUSE-SU-2023:3969-1","SUSE-SU-2023:3971-1","SUSE-SU-2023:3988-1","SUSE-SU-2023:4057-1","SUSE-SU-2023:4058-1","SUSE-SU-2024:2894-1","SUSE-SU-2024:2929-1","SUSE-SU-2024:2947-1"],"details":"An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c.","affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37453.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"6.4.2"}]}]}}],"references":[{"type":"WEB","url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=de28e469da75359a2bb8cd8778b78aa64b1be1f4"},{"type":"WEB","url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ff33299ec8bb80cdcc073ad9c506bd79bb2ed20b"},{"type":"WEB","url":"https://lore.kernel.org/all/000000000000c0ffe505fe86c9ca%40google.com/T/"},{"type":"WEB","url":"https://lore.kernel.org/all/000000000000e56434059580f86e%40google.com/T/"},{"type":"WEB","url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1e4c574225cc5a0553115e5eb5787d1474db5b0f"},{"type":"WEB","url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=85d07c55621676d47d873d2749b88f783cd4d5a1"},{"type":"EVIDENCE","url":"https://syzkaller.appspot.com/bug?extid=18996170f8096c6174d0"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}