CVE-2023-53015

Updated: 2026-02-27 03:28:10.01005

Description:

In the Linux kernel, the following vulnerability has been resolved: HID: betop: check shape of output reports betopff_init() only checks the total sum of the report counts for each report field to be at least 4, but hid_betopff_play() expects 4 report fields. A device advertising an output report with one field and 4 report counts would pass the check but crash the kernel with a NULL pointer dereference in hid_betopff_play().


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-05-07 04:14:15 This bug is confined to the Linux HID betop force‑feedback driver for certain game controllers and...
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-05-07 04:14:18 Ignored due to low severity
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-05-07 04:14:19 Ignored due to low severity
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-06-10 04:29:39 Ignored due to low severity
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Already Fixed 2025-04-24 03:59:41
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Released CLSA-2025:1747430034 2025-05-18 05:07:16
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Already Fixed 2025-04-25 03:48:51