Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-53062


In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc95xx: Limit packet length to skb->len Packet length retrieved from descriptor may be larger than the actual socket buffer length. In such case the cloned skb passed up the network stack will leak kernel memory contents.


Published

2025-05-02T16:15:25.257

Last Modified

2025-11-07T02:23:30.780

Status

Analyzed

Source

416baaa9-dc9f-4396-8d5f-8c081fb06d67

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-401

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 4.14.312 Yes
Operating System linux linux_kernel < 4.19.280 Yes
Operating System linux linux_kernel < 5.4.240 Yes
Operating System linux linux_kernel < 5.10.177 Yes
Operating System linux linux_kernel < 5.15.105 Yes
Operating System linux linux_kernel < 6.1.22 Yes
Operating System linux linux_kernel < 6.2.9 Yes
Operating System linux linux_kernel 6.3 Yes
Operating System linux linux_kernel 6.3 Yes
Operating System linux linux_kernel 6.3 Yes

References