PT-2025-18812 · Linux+3 · Linux Kernel+3

Published

2023-02-16

·

Updated

2026-01-28

·

CVE-2023-53048

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A warning in the Linux kernel has been resolved. The issue occurs when handling a discover identity message in the USB typec tcpm module. This warning can be triggered by specific sequences of events, including the reception of a discover identity message from a partner device. The state machine could still send out a discover identity message later if the current message is skipped, resulting in a warning. To fix this, the received message is handled first, and the pending discover identity message is overridden without warning.
Recommendations For Linux kernel versions prior to the fixed version, consider applying the fix that handles the received discover identity message firstly and overrides the pending discover identity message without warning. As a temporary workaround, consider disabling the tcpm queue vdm function until a patch is available. Restrict access to the vulnerable tcpm module to minimize the risk of exploitation. Avoid using the vdm state variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06836
CVE-2023-53048
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse