CVE-2023-53125
published 2025-05-02CVE-2023-53125: In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Limit packet length to skb->len Packet length retrieved from skb data…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Limit packet length to skb->len
Packet length retrieved from skb data may be larger than
the actual socket buffer length (up to 9026 bytes). In such
case the cloned skb passed up the network stack will leak
kernel memory contents.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 4a4de0a68b18485c68ab4f0cfa665b1633c6d277 | 4a4de0a68b18485c68ab4f0cfa665b1633c6d277 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 53966d572d056d6b234cfe76a5f9d60049d3c178 | 53966d572d056d6b234cfe76a5f9d60049d3c178 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 9fabdd79051a9fe51388df099aff6e4b660fedd2 | 9fabdd79051a9fe51388df099aff6e4b660fedd2 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < e294f0aa47e4844f3d3c8766c02accd5a76a7d4e | e294f0aa47e4844f3d3c8766c02accd5a76a7d4e |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 105db6574281e1e03fcbf87983f4fee111682306 | 105db6574281e1e03fcbf87983f4fee111682306 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < c7bdc137ca163b90917c1eeba4f1937684bd4f8b | c7bdc137ca163b90917c1eeba4f1937684bd4f8b |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 8ee5df9c039e37b9d8eb5e3de08bfb7f53d31cb6 | 8ee5df9c039e37b9d8eb5e3de08bfb7f53d31cb6 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < d8b228318935044dafe3a5bc07ee71a1f1424b8d | d8b228318935044dafe3a5bc07ee71a1f1424b8d |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 2.6.35 < 4.14.311 | 4.14.311 |
| linux | linux_kernel | >= 4.15 < 4.19.279 | 4.19.279 |
| linux | linux_kernel | >= 4.20 < 5.4.238 | 5.4.238 |
| linux | linux_kernel | >= 5.11 < 5.15.104 | 5.15.104 |
| linux | linux_kernel | >= 5.16 < 6.1.21 | 6.1.21 |
| linux | linux_kernel | >= 5.5 < 5.10.176 | 5.10.176 |
| linux | linux_kernel | >= 6.2 < 6.2.8 | 6.2.8 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53125: In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Limit packet length to skb->len Packet length retrieved from s
osv·2025-05-02·CVSS 5.5
CVE-2023-53125 [MEDIUM] CVE-2023-53125: In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Limit packet length to skb->len Packet length retrieved from s
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Limit packet length to skb->len Packet length retrieved from skb data may be larger than the actual socket buffer length (up to 9026 bytes). In such case the cloned skb passed up the network stack will leak kernel memory contents.
GHSA
GHSA-p8mj-x7w2-cp95: In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Limit packet length to skb->len
Packet length retrieved from
ghsa_unreviewed·2025-05-02
CVE-2023-53125 [MEDIUM] CWE-401 GHSA-p8mj-x7w2-cp95: In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Limit packet length to skb->len
Packet length retrieved from
In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Limit packet length to skb->len
Packet length retrieved from skb data may be larger than
the actual socket buffer length (up to 9026 bytes). In such
case the cloned skb passed up the network stack will leak
kernel memory contents.
Red Hat
kernel: net: usb: smsc75xx: Limit packet length to skb->len
vendor_redhat·2025-05-02·CVSS 5.5
CVE-2023-53125 [MEDIUM] CWE-125 kernel: net: usb: smsc75xx: Limit packet length to skb->len
kernel: net: usb: smsc75xx: Limit packet length to skb->len
In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Limit packet length to skb->len
Packet length retrieved from skb data may be larger than
the actual socket buffer length (up to 9026 bytes). In such
case the cloned skb passed up the network stack will leak
kernel memory contents.
Statement: The vulnerability in SMSC LAN75XX based USB 2.0 gigabit ethernet devices driver arises because the driver fails to properly validate packet length fields when receiving network frames. Specifically, the code used size values that could exceed the actual skb->len, leading to a situation where kernel memory beyond the buffer is copied into the outgoing skb. If the driver is active, a remote attacker on the
Debian
CVE-2023-53125: linux - In the Linux kernel, the following vulnerability has been resolved: net: usb: s...
vendor_debian·2023·CVSS 5.5
CVE-2023-53125 [MEDIUM] CVE-2023-53125: linux - In the Linux kernel, the following vulnerability has been resolved: net: usb: s...
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc75xx: Limit packet length to skb->len Packet length retrieved from skb data may be larger than the actual socket buffer length (up to 9026 bytes). In such case the cloned skb passed up the network stack will leak kernel memory contents.
Scope: local
bookworm: resolved (fixed in 6.1.25-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.25-1)
sid: resolved (fixed in 6.1.25-1)
trixie: resolved (fixed in 6.1.25-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/105db6574281e1e03fcbf87983f4fee111682306https://git.kernel.org/stable/c/4a4de0a68b18485c68ab4f0cfa665b1633c6d277https://git.kernel.org/stable/c/53966d572d056d6b234cfe76a5f9d60049d3c178https://git.kernel.org/stable/c/8ee5df9c039e37b9d8eb5e3de08bfb7f53d31cb6https://git.kernel.org/stable/c/9fabdd79051a9fe51388df099aff6e4b660fedd2https://git.kernel.org/stable/c/c7bdc137ca163b90917c1eeba4f1937684bd4f8bhttps://git.kernel.org/stable/c/d8b228318935044dafe3a5bc07ee71a1f1424b8dhttps://git.kernel.org/stable/c/e294f0aa47e4844f3d3c8766c02accd5a76a7d4e
2025-05-02
Published