cbcvebase.
CVE-2023-53840
published 2025-12-09

CVE-2023-53840: In the Linux kernel, the following vulnerability has been resolved: usb: early: xhci-dbc: Fix a potential out-of-bound memory access If xdbc_bulk_write()…

PriorityP420medium6.1
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: early: xhci-dbc: Fix a potential out-of-bound memory access If xdbc_bulk_write() fails, the values in 'buf' can be anything. So the string is not guaranteed to be NULL terminated when xdbc_trace() is called. Reserve an extra byte, which will be zeroed automatically because 'buf' is a static variable, in order to avoid troubles, should it happen.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= aeb9dd1de98c1a5f2007ea5d2a154c1244caf8a0 < e8fb0f13e45cf361fd06593d3cb2d89915cd3bd0e8fb0f13e45cf361fd06593d3cb2d89915cd3bd0
linuxlinux>= aeb9dd1de98c1a5f2007ea5d2a154c1244caf8a0 < 351c8d8650d1ccc006255fa01f98b6c6496a02e5351c8d8650d1ccc006255fa01f98b6c6496a02e5
linuxlinux>= aeb9dd1de98c1a5f2007ea5d2a154c1244caf8a0 < df7c8aba7309f4dc55df94e06b67f576c0f52406df7c8aba7309f4dc55df94e06b67f576c0f52406
linuxlinux>= aeb9dd1de98c1a5f2007ea5d2a154c1244caf8a0 < a4a97ab3db5c081eb6e7dba91306adefb461e0bda4a97ab3db5c081eb6e7dba91306adefb461e0bd
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 4.12.0 < 5.15.995.15.99
linuxlinux_kernel>= 5.16.0 < 6.1.166.1.16
linuxlinux_kernel>= 6.2.0 < 6.2.36.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.