CVE-2023-53125
MEDIUMLinux Kernel 2.6.35-4.14.311 - Use-After-Free in USB SMSC75XX Packet Length Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Limit packet length to skb->len Packet length retrieved from skb data may be larger than the actual socket buffer length (up to 9026 bytes). In such case the cloned skb passed up the network stack will leak kernel memory contents.
References (8)
Core 8
Core References
Scores
CVSS v3
5.5
EPSS
0.0015
EPSS Percentile
4.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-401
Status
published
Products (21)
Linux/Linux
< 2.6.34
Linux/Linux
2.6.34
Linux/Linux
4.14.311 - 4.14.*
Linux/Linux
4.19.279 - 4.19.*
Linux/Linux
5.10.176 - 5.10.*
Linux/Linux
5.15.104 - 5.15.*
Linux/Linux
5.4.238 - 5.4.*
Linux/Linux
6.1.21 - 6.1.*
Linux/Linux
6.2.8 - 6.2.*
Linux/Linux
6.3
... and 11 more
Published
May 02, 2025
Tracked Since
Feb 18, 2026