PT-2025-18836 · Linux+4 · Linux Kernel+4

CVE-2023-53072

·

Publicado

2023-03-10

·

Atualizado

2026-05-26

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.2.0-rc59af4eaa31c1f6c00c8f1e448ed99a45c66340dd5
Description A use-after-free (UaF) issue was reported in the Linux kernel, specifically in the mptcp module, at token lookup time after refactoring the passive socket initialization part. The issue occurs when the token bucket busy function attempts to read from a freed memory address. This is caused by the improper cleanup of paired MPTCP-level resources when an unaccepted subflow is destroyed by TCP internals. The estimated number of potentially affected devices is not provided.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the mptcp module, ensuring that the mptcp destroy sock function is always called on msk sockets, even on accepted ones. As a temporary workaround, consider disabling the mptcp module until a patch is available. Restrict access to the vulnerable mptcp token new connect function to minimize the risk of exploitation. Avoid using the mptcp sendmsg function in the affected API endpoint until the issue is resolved.

Exploit

Correção

DoS

Improper Initialization

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
BDU:2026-03974
CESA-2024_3138
CVE-2023-53072
RHSA-2023:6583
RHSA-2023_6583
RHSA-2024:3138
RHSA-2024_3138

Produtos afetados

Centos
Debian
Linux Kernel
Red Hat
Red Os