PT-2025-40186 · Linux+3 · Linux Kernel+3

Publicado

2023-07-18

·

Atualizado

2025-11-19

·

CVE-2023-53479

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the CXL driver within the Linux kernel, specifically in the cxl parse cfmws() function. The problem occurs in the cxl decoder add() fail path, where memory pointed to by cxld is released via put device() and subsequently accessed. This results in a use-after-free condition detected by KASAN and KFENCE. The issue is addressed by using local variables within the dev err() function instead of referencing the released memory, and by changing the print format specifier to %pr.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
BDU:2026-06103
CVE-2023-53479
RHSA-2023:6583
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1

Produtos afetados

Astra Linux
Linux Kernel
Red Hat
Suse