SB2025091931 - Memory leak in Linux kernel gadget udc driver
Published: September 19, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2023-53406)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the DEFINE_SHOW_ATTRIBUTE() function in drivers/usb/gadget/udc/pxa25x_udc.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6236a6d2cdfb710bd8a82c4b179d0a034d0d99cb
- https://git.kernel.org/stable/c/78d9586d8e728be1e360d3d0da7170c791d1d55e
- https://git.kernel.org/stable/c/7a038a681b7df78362d9fc7013e5395a694a9d3a
- https://git.kernel.org/stable/c/8d48a7887dbca22e064c20caf20ae7949019fe9b
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.5