CVE-2023-25012: Use After Free
Published Feb 1, 2023
·Updated
Last updated 25 April 2025
Other sources
The Linux kernel through 6.1.9 has a Use-After-Free in bigbenremove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.
— Launchpad
Affected Software
3 affected componentsFixes available
Google Android
Linux Linux Kernel<=6.1.9
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.27-1
Remediation
Event History
Feb 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 2, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Mar 28, 2024
Data Sourced
via Launchpad·12:47 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:10 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-25012?
CVE-2023-25012 has been classified with a medium severity due to its use-after-free vulnerability in the Linux kernel.
2
How do I fix CVE-2023-25012?
To fix CVE-2023-25012, update to a patched version of the Linux kernel that is 6.1.123 or newer.
3
Which versions of the Linux kernel are affected by CVE-2023-25012?
CVE-2023-25012 affects all Linux kernel versions up to and including 6.1.9.
4
What causes CVE-2023-25012 in the Linux kernel?
CVE-2023-25012 is caused by a use-after-free issue in the bigben_remove function when managing LED controllers.
5
Is CVE-2023-25012 specific to any operating systems?
CVE-2023-25012 is primarily affecting the Linux kernel but may also impact Android devices utilizing the kernel version mentioned.