Bug 2363686 (CVE-2023-53125)

Summary: CVE-2023-53125 kernel: net: usb: smsc75xx: Limit packet length to skb->len
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dfreiber, drow, jburrell, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2025-05-02 16:01:41 UTC
In the Linux kernel, the following vulnerability has been resolved:

net: usb: smsc75xx: Limit packet length to skb->len

Packet length retrieved from skb data may be larger than
the actual socket buffer length (up to 9026 bytes). In such
case the cloned skb passed up the network stack will leak
kernel memory contents.

Comment 1 Avinash Hanwate 2025-05-05 05:00:46 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025050232-CVE-2023-53125-67cf@gregkh/T

Comment 3 errata-xmlrpc 2025-09-15 10:38:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:15785 https://access.redhat.com/errata/RHSA-2025:15785

Comment 4 errata-xmlrpc 2025-09-23 00:36:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:16398 https://access.redhat.com/errata/RHSA-2025:16398

Comment 5 errata-xmlrpc 2025-09-30 17:21:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:17109 https://access.redhat.com/errata/RHSA-2025:17109

Comment 6 errata-xmlrpc 2025-10-01 17:40:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:17161 https://access.redhat.com/errata/RHSA-2025:17161

Comment 7 errata-xmlrpc 2025-10-14 08:27:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:17958 https://access.redhat.com/errata/RHSA-2025:17958

Comment 9 errata-xmlrpc 2025-10-20 00:07:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:18279 https://access.redhat.com/errata/RHSA-2025:18279

Comment 10 errata-xmlrpc 2025-10-20 00:19:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:18280 https://access.redhat.com/errata/RHSA-2025:18280

Comment 12 errata-xmlrpc 2025-10-22 00:23:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:18932 https://access.redhat.com/errata/RHSA-2025:18932