CVE-2023-53551NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4

Description

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Add null pointer check in gserial_resume Consider a case where gserial_disconnect has already cleared gser->ioport. And if a wakeup interrupt triggers afterwards, gserial_resume gets called, which will lead to accessing of gser->ioport and thus causing null pointer dereference.Add a null pointer check to prevent this. Added a static spinlock to prevent gser->ioport from becoming null after the newly add

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.85.10.171+3
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxaba3a8d01d623a5efef48ab8e78752d58d4c90c3c5360eec648bd506afa304ae4a71f82e13d41897+5
debiandebian/linux< linux 6.1.15-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53551: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Add null pointer check in gserial_resume Consider a case wh2025-10-04
GHSA
GHSA-x2mg-85cj-xc8q: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Add null pointer check in gserial_resume Consider a case2025-10-04

📋Vendor Advisories

2
Red Hat
kernel: usb: gadget: u_serial: Add null pointer check in gserial_resume2025-10-04
Debian
CVE-2023-53551: linux - In the Linux kernel, the following vulnerability has been resolved: usb: gadget...2023