CVE-2023-25012: Linux Kernel

Medium severity, CVSS 4.6. EPSS: 0.8% chance of exploitation in the next 30 days.

The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.

Affected products

  • Linux Linux Kernel: up to and including 6.1.9

Published 2023-02-02. Last modified 2026-06-17.