
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-54270 is a use-after-free (UAF) vulnerability in the Linux kernel's media USB Siano driver, specifically caused by the do_submit_urb() function. The flaw was published on December 30, 2025, and affects the Linux kernel across multiple stable branches. It is classified as medium severity with an estimated CVSS category of MEDIUM (Feedly). The EPSS score is approximately 0.024%, indicating a low probability of exploitation in the wild (Feedly).
The vulnerability is a use-after-free bug (CWE-416) in the media/usb/siano subsystem of the Linux kernel. The do_submit_urb() function can trigger access to already-freed memory, as demonstrated by a KASan report showing a read of 8 bytes at a freed address within worker_thread(). The bug was identified using KASAN (Kernel Address Sanitizer) on kernel version 6.2.0-rc3, where a worker thread accesses a freed object, leading to potential memory corruption (Feedly). Fixes were applied across multiple stable kernel branches via commits to the kernel stable tree (Linux Kernel Git).
Successful exploitation of this vulnerability could allow a local attacker or a malicious USB device to trigger memory corruption in the kernel, potentially leading to a system crash (denial of service) or, in more severe scenarios, privilege escalation or arbitrary code execution in kernel context. The affected component is the Siano USB media driver, so systems with this driver loaded and USB access available are at risk. The confidentiality and integrity impact depends on the attacker's ability to control the freed memory region after the UAF condition is triggered (Feedly).
The fix has been applied to multiple Linux kernel stable branches via patches committed to the kernel stable tree (commits 19aadf0eb70e, 42f8ba835568, 114f768e7314, 1477b00ff582, and 479796534a45) (Linux Kernel Git). Users should update to a patched kernel version as provided by their Linux distribution (e.g., SUSE has issued advisories referencing this CVE) (Linux Security). As a workaround, systems that do not require the Siano USB media driver can blacklist the smsusb kernel module to prevent the vulnerable code from loading.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."