CVE-2023-53410Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: USB: ULPI: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel6.26.2.5+1
Debianlinux/linux_kernel< 6.1.20-1+2
CVEListV5linux/linuxbd0a0a024f2a41e7cc8eadb9862f82c45884b69cdcbe69f4f743a938344b32e60531ea55355e0c08+3
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53410: In the Linux kernel, the following vulnerability has been resolved: USB: ULPI: fix memory leak with using debugfs_lookup() When calling debugfs_lookup2025-09-18
GHSA
GHSA-xcxp-6m6x-8jpj: In the Linux kernel, the following vulnerability has been resolved: USB: ULPI: fix memory leak with using debugfs_lookup() When calling debugfs_look2025-09-18

📋Vendor Advisories

3
Red Hat
kernel: USB: ULPI: fix memory leak with using debugfs_lookup()2025-09-18
Microsoft
USB: ULPI: fix memory leak with using debugfs_lookup()2025-09-09
Debian
CVE-2023-53410: linux - In the Linux kernel, the following vulnerability has been resolved: USB: ULPI: ...2023
CVE-2023-53410 — Linux vulnerability | cvebase