PT-2024-14674 · Linux+6 · Linux Kernel+6

Sili Luo

·

Published

2024-02-14

·

Updated

2025-09-29

·

CVE-2023-52637

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.5.0-rc5
Description The vulnerability is a use-after-free (UAF) bug in the j1939 sk match filter function during setsockopt(SO J1939 FILTER) calls. This occurs when the setsockopt call modifies the jsk->filters while receiving packets, and the jsk->sk is not properly locked to prevent the UAF. The bug can be triggered by a slab-use-after-free in j1939 sk recv match one, which can lead to a read of size 4 at an invalid address.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, versions 6.5.0-rc5 and later should be used. For versions prior to 6.5.0-rc5, consider applying the patch that fixes the UAF bug in j1939 sk match filter. As a temporary workaround, consider disabling the j1939 sk match filter function until a patch is available. However, this may have performance implications and should be carefully evaluated before implementation.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2025-07479
CVE-2023-52637
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_9315
OESA-2024-1617
OESA-2024-1618
OESA-2024-1622
OESA-2024-1647
OESA-2024-1648
OESA-2024-1649
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6767-1
USN-6767-2
USN-6795-1
USN-6828-1
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6900-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu