CVE-2023-53125

MEDIUM

Linux Kernel 2.6.35-4.14.311 - Use-After-Free in USB SMSC75XX Packet Length Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Limit packet length to skb->len Packet length retrieved from skb data may be larger than the actual socket buffer length (up to 9026 bytes). In such case the cloned skb passed up the network stack will leak kernel memory contents.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (21)
Linux/Linux < 2.6.34
Linux/Linux 2.6.34
Linux/Linux 4.14.311 - 4.14.*
Linux/Linux 4.19.279 - 4.19.*
Linux/Linux 5.10.176 - 5.10.*
Linux/Linux 5.15.104 - 5.15.*
Linux/Linux 5.4.238 - 5.4.*
Linux/Linux 6.1.21 - 6.1.*
Linux/Linux 6.2.8 - 6.2.*
Linux/Linux 6.3
... and 11 more
Published May 02, 2025
Tracked Since Feb 18, 2026