CVE-2023-53437
published 2025-09-18CVE-2023-53437: In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Handle cameras with invalid descriptors If the source entity does not…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Handle cameras with invalid descriptors
If the source entity does not contain any pads, do not create a link.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 4.14.224 < 4.14.308 | 4.14.308 |
| linux | linux | >= 4.19.179 < 4.19.276 | 4.19.276 |
| linux | linux | >= 4.4.260 < 4.5 | 4.5 |
| linux | linux | >= 4.9.260 < 4.10 | 4.10 |
| linux | linux | >= 5.10.21 < 5.10.173 | 5.10.173 |
| linux | linux | >= 5.11.4 < 5.12 | 5.12 |
| linux | linux | >= 5.4.103 < 5.4.235 | 5.4.235 |
| linux | linux | >= 6d30cf81ee3c0368175f76c03120af5d81e0c639 < c8f4a424af5879baefb0fb8a8a09b09ea1779483 | c8f4a424af5879baefb0fb8a8a09b09ea1779483 |
| linux | linux | >= 7532dad6634031d083df7af606fac655b8d08b5c < 31a8d11d28b57656cebfbd4c0b8b76f6ad5b017d | 31a8d11d28b57656cebfbd4c0b8b76f6ad5b017d |
| linux | linux | >= 7532dad6634031d083df7af606fac655b8d08b5c < 11196ee3916e50a5da3c1e6ecda19a02dca14ba3 | 11196ee3916e50a5da3c1e6ecda19a02dca14ba3 |
| linux | linux | >= 7532dad6634031d083df7af606fac655b8d08b5c < 1a76cfc388cf105d3e04ac592670a52a3864b1ba | 1a76cfc388cf105d3e04ac592670a52a3864b1ba |
| linux | linux | >= 7532dad6634031d083df7af606fac655b8d08b5c < 41ddb251c68ac75c101d3a50a68c4629c9055e4c | 41ddb251c68ac75c101d3a50a68c4629c9055e4c |
| linux | linux | >= aa1362606059ade437a901fe7c33b24901683c14 < 4e4e6ca62e77539d4df8d13137e2683b10baddd9 | 4e4e6ca62e77539d4df8d13137e2683b10baddd9 |
| linux | linux | >= b4759a52b8940dbbfc565c918a3893ecaeb5b134 < 2914259fcea23971c6fed8b2618d3a729a78c365 | 2914259fcea23971c6fed8b2618d3a729a78c365 |
| linux | linux | >= cc52ed14f5ca849ef81e6a6bc4beea6dc43514d0 < d8aa2e1ae6426d7cbddf1735aed1a63ddf0e6909 | d8aa2e1ae6426d7cbddf1735aed1a63ddf0e6909 |
| linux | linux_kernel | < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: media: uvcvideo: Handle cameras with invalid descriptors
vendor_redhat·2025-09-18·CVSS 5.5
CVE-2023-53437 [MEDIUM] CWE-20 kernel: media: uvcvideo: Handle cameras with invalid descriptors
kernel: media: uvcvideo: Handle cameras with invalid descriptors
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Handle cameras with invalid descriptors
If the source entity does not contain any pads, do not create a link.
Statement: This patch addresses a potential invalid memory access in the UVC (USB Video Class) subsystem when handling malformed or incomplete camera descriptors. Previously, a missing or invalid source entity without pads could cause link creation to fail with undefined behavior.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package
Debian
CVE-2023-53437: linux - In the Linux kernel, the following vulnerability has been resolved: media: uvcv...
vendor_debian·2023·CVSS 5.5
CVE-2023-53437 [MEDIUM] CVE-2023-53437: linux - In the Linux kernel, the following vulnerability has been resolved: media: uvcv...
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Handle cameras with invalid descriptors If the source entity does not contain any pads, do not create a link.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
OSV
CVE-2023-53437: In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Handle cameras with invalid descriptors If the source entity does
osv·2025-09-18·CVSS 5.5
CVE-2023-53437 [MEDIUM] CVE-2023-53437: In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Handle cameras with invalid descriptors If the source entity does
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Handle cameras with invalid descriptors If the source entity does not contain any pads, do not create a link.
GHSA
GHSA-fffv-2q69-3rfg: In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Handle cameras with invalid descriptors
If the source entity do
ghsa_unreviewed·2025-09-18
CVE-2023-53437 [MEDIUM] GHSA-fffv-2q69-3rfg: In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Handle cameras with invalid descriptors
If the source entity do
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Handle cameras with invalid descriptors
If the source entity does not contain any pads, do not create a link.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/11196ee3916e50a5da3c1e6ecda19a02dca14ba3https://git.kernel.org/stable/c/1a76cfc388cf105d3e04ac592670a52a3864b1bahttps://git.kernel.org/stable/c/2914259fcea23971c6fed8b2618d3a729a78c365https://git.kernel.org/stable/c/31a8d11d28b57656cebfbd4c0b8b76f6ad5b017dhttps://git.kernel.org/stable/c/41ddb251c68ac75c101d3a50a68c4629c9055e4chttps://git.kernel.org/stable/c/4e4e6ca62e77539d4df8d13137e2683b10baddd9https://git.kernel.org/stable/c/c8f4a424af5879baefb0fb8a8a09b09ea1779483https://git.kernel.org/stable/c/d8aa2e1ae6426d7cbddf1735aed1a63ddf0e6909
2025-09-18
Published