cbcvebase.
CVE-2023-54270
published 2025-12-30

CVE-2023-54270: In the Linux kernel, the following vulnerability has been resolved: media: usb: siano: Fix use after free bugs caused by do_submit_urb There are UAF bugs…

PriorityP422low4.3
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: media: usb: siano: Fix use after free bugs caused by do_submit_urb There are UAF bugs caused by do_submit_urb(). One of the KASan reports is shown below: [ 36.403605] BUG: KASAN: use-after-free in worker_thread+0x4a2/0x890 [ 36.406105] Read of size 8 at addr ffff8880059600e8 by task kworker/0:2/49 [ 36.408316] [ 36.408867] CPU: 0 PID: 49 Comm: kworker/0:2 Not tainted 6.2.0-rc3-15798-g5a41237ad1d4-dir8 [ 36.411696] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g15584 [ 36.416157] Workqueue: 0x0 (events) [ 36.417654] Call Trace: [ 36.418546] [ 36.419320] dump_stack_lvl+0x96/0xd0 [ 36.420522] print_address_description+0x75/0x350 [ 36.421992] print_report+0x11b/0x250 [ 36.423174] ? _raw_spin_lock_irqsave+0x87/0xd0 [ 36.424806] ? __virt_addr_valid+0xcf/0x170 [ 36.426069] ? worker_thread+0x4a2/0x890 [ 36.427355] kasan_report+0x131/0x160 [ 36.428556] ? worker_thread+0x4a2/0x890 [ 36.430053] worker_thread+0x4a2/0x890 [ 36.431297] ? worker_clr_flags+0x90/0x90 [ 36.432479] kthread+0x166/0x190 [ 36.433493] ? kthread_blkcg+0x50/0x50 [ 36.434669] ret_from_fork+0x22/0x30 [ 36.435923] [ 36.436684] [ 36.437215] Allocated by task 24: [ 36.438289] kasan_set_track+0x50/0x80 [ 36.439436] __kasan_kmalloc+0x89/0xa0 [ 36.440566] smsusb_probe+0x374/0xc90 [ 36.441920] usb_probe_interface+0x2d1/0x4c0 [ 36.443253] really_probe+0x1d5/0x580 [ 36.444539] __driver_probe_device+0xe3/0x130 [ 36.446085] driver_probe_device+0x49/0x220 [ 36.447423] __device_attach_driver+0x19e/0x1b0 [ 36.448931] bus_for_each_drv+0xcb/0x110 [ 36.450217] __device_attach+0x132/0x1f0 [ 36.451470] bus_probe_device+0x59/0xf0 [ 36.452563] device_add+0x4ec/0x7b0 [ 36.453830] usb_set_configuration+0xc63/0xe10 [ 36.455230] usb_generic_driver_probe+0x3b/0x80 [ 36.456166] printk: console [ttyGS0] disabled [ 36.456569] usb_probe_device+0x90/0x110 [ 36.459523] really_probe+0x1d5/0x580 [ 36.461027] __driver_probe_device+0xe3/0x130 [ 36.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < c379272ea9c2ee36f0a1327b0fb8889c975093f7c379272ea9c2ee36f0a1327b0fb8889c975093f7
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < 1477b00ff582970df110fc9e15a5e2021acb92221477b00ff582970df110fc9e15a5e2021acb9222
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < a41bb59eff7a58a6772f84a5b70ad7ec26dad074a41bb59eff7a58a6772f84a5b70ad7ec26dad074
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < 42f8ba8355682f6c4125b75503cac0cef4ac91d342f8ba8355682f6c4125b75503cac0cef4ac91d3
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < 114f768e7314ca9e1fdbebe11267c4403e89e7f2114f768e7314ca9e1fdbebe11267c4403e89e7f2
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < 479796534a450fd44189080d51bebefa3b42c6fc479796534a450fd44189080d51bebefa3b42c6fc
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < 19aadf0eb70edae7180285dbb9bfa237d1ddb34d19aadf0eb70edae7180285dbb9bfa237d1ddb34d
linuxlinux>= dd47fbd40e6ea6884e295e13a2e50b0894258fdf < ebad8e731c1c06adf04621d6fd327b860c0861b5ebad8e731c1c06adf04621d6fd327b860c0861b5
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 4.15.0 < 4.19.2764.19.276
linuxlinux_kernel>= 4.20.0 < 5.4.2355.4.235
linuxlinux_kernel>= 4.6.0 < 4.14.3084.14.308
linuxlinux_kernel>= 5.11.0 < 5.15.995.15.99
linuxlinux_kernel>= 5.16.0 < 6.1.166.1.16
linuxlinux_kernel>= 5.5.0 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2.0 < 6.2.36.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.