SB2025091920 - Memory leak in Linux kernel usb host driver
Published: September 19, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-53416)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the create_debug_file() function in drivers/usb/host/isp1362-hcd.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/9d537c35e48feba9d450acca0ff14a55ce1ec450
- https://git.kernel.org/stable/c/b0a8195a84a725ca7936c213b5e056d2a3ab2a94
- https://git.kernel.org/stable/c/c26e682afc14caa87d44beed271eec8991e93c65
- https://git.kernel.org/stable/c/fb284bee1e213c94be9131d1aca7c16bd6ba259d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.100