vulnerability

Debian: CVE-2023-53840: linux -- security update

Severity
5
CVSS
(AV:L/AC:L/Au:S/C:P/I:N/A:C)
Published
Dec 10, 2025
Added
Dec 10, 2025
Modified
Dec 18, 2025

Description

In the Linux kernel, the following vulnerability has been resolved: usb: early: xhci-dbc: Fix a potential out-of-bound memory access If xdbc_bulk_write() fails, the values in 'buf' can be anything. So the string is not guaranteed to be NULL terminated when xdbc_trace() is called. Reserve an extra byte, which will be zeroed automatically because 'buf' is a static variable, in order to avoid troubles, should it happen.

Solution

debian-upgrade-linux
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.