Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: pxa25x_udc: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.15.100 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/6236a6d2cdfb710bd8a82c4b179d0a034d0d99cbPatch
- https://git.kernel.org/stable/c/78d9586d8e728be1e360d3d0da7170c791d1d55ePatch
- https://git.kernel.org/stable/c/7a038a681b7df78362d9fc7013e5395a694a9d3aPatch
- https://git.kernel.org/stable/c/8d48a7887dbca22e064c20caf20ae7949019fe9bPatch
FAQ
What is CVE-2023-53406?
CVE-2023-53406 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: USB: gadget: pxa25x_udc: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() cal...
How severe is CVE-2023-53406?
CVE-2023-53406 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53406?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.