Red Hat remediated CVE-2023-1073, a moderate-severity Linux kernel flaw in the Human Interface Device (HID) subsystem. A locally authenticated, low-privilege attacker with physical access could attach a crafted USB HID device whose descriptor creates an empty report list, causing hid_validate_values() to invoke list_entry() on an invalid entry. The resulting type confusion can produce an out-of-bounds write and memory corruption, potentially causing a system crash or local privilege escalation; Red Hat assigned CVSS 6.6.
The underlying HID report-list issues were reported in hid_validate_values() and bigben_probe(), and upstream patches added checks requiring non-empty lists before the entries are used. The fix landed upstream in Linux 6.1.9 and was distributed through Fedora stable updates. Red Hat released corrected kernel packages for RHEL 8 and 9, relevant RHEL 8 Extended Update Support streams, kernel-rt packages, and Red Hat Virtualization 4 on RHEL 8; the RHEL 8.8 EUS kernel update 4.18.0-477.43.1.el8_8 includes the remediation. Administrators should apply the applicable kernel update and reboot systems to activate it; RHEL 6 is not affected and RHEL 7 is outside support scope.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2024:0575, an Important RHEL 8.8 Extended Update Support kernel update containing the fix for CVE-2023-1073. The update provided kernel version 4.18.0-477.43.1.el8_8 and required a reboot for the fix to take effect.
Alex reported the HID hid_validate_values() empty-report-list validation issue, which Red Hat tracked as Bug 2173403 and later assigned CVE-2023-1073.
Red Hat addressed CVE-2023-1073 in RHEL 9 through RHSA-2023:6583 and in RHEL 8 through RHSA-2023:6901 and RHSA-2023:7077.
The upstream fix for CVE-2023-1073 was included in Linux kernel version 6.1.9 and subsequently delivered to Fedora through stable kernel updates.
Pietro Borrello disclosed unchecked list_entry() uses in the Linux HID driver, including hid_validate_values(), which malicious HID descriptors with empty report lists could trigger. Patches were submitted to require non-empty report lists before use.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.