CVE-2023-53062
MEDIUMLinux Kernel 2.6.28-4.14.311 - Information Disclosure via SMSC95XX USB Network Packet Length Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc95xx: Limit packet length to skb->len Packet length retrieved from descriptor may be larger than the actual socket buffer length. In such case the cloned skb passed up the network stack will leak kernel memory contents.
References (8)
Core 8
Core References
Scores
CVSS v3
5.5
EPSS
0.0016
EPSS Percentile
5.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (20)
Linux/Linux
< 2.6.28
Linux/Linux
2.6.28
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - 33d1603a38e05886c538129ddfe00bd52d347e7b
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - 70eb25c6a6cde149affe8a587371a3a8ad295ba0
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - 733580e268a53db1cd01f2251419da91866378f6
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - ba6c40227108f8ee428e42eb0337b48ed3001e65
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - d3c145a4d24b752c9a1314d5a595014d51471418
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - e041bef1adee02999cf24f9a2e15ed452bc363fe
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - f2111c791d885211714db85f9a06188571c57dd0
Linux/Linux
2f7ca802bdae2ca41022618391c70c2876d92190 - ff821092cf02a70c2bccd2d19269f01e29aa52cf
... and 10 more
Published
May 02, 2025
Tracked Since
Feb 18, 2026