cbcvebase.
CVE-2023-53196
published 2025-09-15

CVE-2023-53196: In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: qcom: Fix potential memory leak Function dwc3_qcom_probe() allocates memory for…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: qcom: Fix potential memory leak Function dwc3_qcom_probe() allocates memory for resource structure which is pointed by parent_res pointer. This memory is not freed. This leads to memory leak. Use stack memory to prevent memory leak. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= 2bc02355f8ba2c1f108ec8b16a673b467a17228c < 648a163cff21ea355c8765e882ba8bf66a870a3e648a163cff21ea355c8765e882ba8bf66a870a3e
linuxlinux>= 2bc02355f8ba2c1f108ec8b16a673b467a17228c < 74f8606ddfa450d2255b4e61472a7632def1e8c474f8606ddfa450d2255b4e61472a7632def1e8c4
linuxlinux>= 2bc02355f8ba2c1f108ec8b16a673b467a17228c < b626cd5e4a87a281629e0c2b07519990077c0fbeb626cd5e4a87a281629e0c2b07519990077c0fbe
linuxlinux>= 2bc02355f8ba2c1f108ec8b16a673b467a17228c < c3b322b84ab5dda7eaca9ded763628b7467734f4c3b322b84ab5dda7eaca9ded763628b7467734f4
linuxlinux>= 2bc02355f8ba2c1f108ec8b16a673b467a17228c < 134a7d4642f11daed6bbc378f930a54dd0322291134a7d4642f11daed6bbc378f930a54dd0322291
linuxlinux>= 2bc02355f8ba2c1f108ec8b16a673b467a17228c < 097fb3ee710d4de83b8d4f5589e8ee13e0f0541e097fb3ee710d4de83b8d4f5589e8ee13e0f0541e
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 5.11 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16 < 6.1.396.1.39
linuxlinux_kernel>= 5.3 < 5.4.2515.4.251
linuxlinux_kernel>= 5.5 < 5.10.1885.10.188
linuxlinux_kernel>= 6.2 < 6.4.46.4.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.