CVE-2023-53068
MEDIUMLinux Kernel < 6.1.22 - Memory Leak
Title source: ruleDescription
In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: Limit packet length to skb->len Packet length retrieved from descriptor may be larger than the actual socket buffer length. In such case the cloned skb passed up the network stack will leak kernel memory contents. Additionally prevent integer underflow when size is less than ETH_FCS_LEN.
Scores
CVSS v3
5.5
EPSS
0.0005
EPSS Percentile
15.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-401
Status
published
Affected Products (4)
linux/linux_kernel
< 6.1.22
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
Timeline
Published
May 02, 2025
Tracked Since
Feb 18, 2026