PT-2025-49738 · Linux+3 · Linux Kernel+3
CVE-2023-53847
·
Published
2025-12-09
·
Updated
2026-07-01
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.3.0-rc7+
Description
The usb-storage alauda subdriver contains a flaw where
alauda check media() does not verify successful USB transfers before utilizing the received data. This can lead to access of uninitialized values. A similar issue exists in alauda get media status(). Additionally, alauda check media() performs Direct Memory Access (DMA) to a buffer on the stack, while a DMA-able buffer is provided by usb-storage for such operations.Recommendations
Update to version 5.3.0-rc7+ or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Linux Kernel
Red Hat
Red Os