Memory Leak Vulnerability in Linux Kernel's USB Gadget for PXA25X UDC
CVE-2023-53406

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2023-53406?

A memory leak vulnerability exists in the USB gadget implementation of the Linux kernel, specifically within the pxa25x_udc subsystem. The issue arises when the function debugfs_lookup() is called without ensuring that dput() is properly invoked, leading to gradual memory consumption. To address this vulnerability effectively, developers are advised to use debugfs_lookup_and_remove(), which simplifies the memory management by handling both operations in one call, thereby preventing memory leaks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 1d50071b53f26a7b8b7d6a0e027b9e6643bb6075 < 6236a6d2cdfb710bd8a82c4b179d0a034d0d99cb

Linux 1d50071b53f26a7b8b7d6a0e027b9e6643bb6075 < 78d9586d8e728be1e360d3d0da7170c791d1d55e

Linux 1d50071b53f26a7b8b7d6a0e027b9e6643bb6075 < 8d48a7887dbca22e064c20caf20ae7949019fe9b

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.