PT-2023-9833 · Linux+7 · Linux Kernel+7

Yuehaibing

·

Published

2023-07-17

·

Updated

2025-09-29

·

CVE-2023-52922

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.4.6
Description The issue is related to a use-after-free vulnerability in the Linux kernel's CAN BCM, specifically in the bcm proc show() function. This vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. The bcm op is freed before the procfs entry is removed in bcm release(), leading to bcm proc show() potentially reading the freed bcm op.
Recommendations To resolve the issue, upgrade the Linux kernel to a version later than 6.4.6. As a temporary workaround, consider restricting access to the vulnerable bcm proc show() function until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:2627
ALSA-2025:3026
ALSA-2025:3027
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALSA-2025_2627
BDU:2025-00165
CESA-2025_3026
CESA-2025_3027
CESA-2025_3049
CVE-2023-52922
INFSA-2025_2627
INFSA-2025_3026
INFSA-2025_3027
OESA-2025-1016
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4346-1
OPENSUSE-SU-2024_4376-1
RHSA-2025:2488
RHSA-2025:2489
RHSA-2025:2490
RHSA-2025:2501
RHSA-2025:2510
RHSA-2025:2512
RHSA-2025:2514
RHSA-2025:2517
RHSA-2025:2524
RHSA-2025:2525
RHSA-2025:2528
RHSA-2025:2627
RHSA-2025:2646
RHSA-2025:3024
RHSA-2025:3025
RHSA-2025:3026
RHSA-2025:3027
RHSA-2025:3048
RHSA-2025:3049
RHSA-2025:3093
RHSA-2025:3094
RHSA-2025:3095
RHSA-2025:3096
RHSA-2025:3097
RHSA-2025:3112
RHSA-2025_2627
RHSA-2025_3026
RHSA-2025_3027
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4345-1
SUSE-SU-2024:4346-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2024_4346-1
SUSE-SU-2025:0236-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
SUSE-SU-2025_0236-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse