PT-2025-13345 · Linux+3 · Linux Kernel+3
Published
2024-04-30
·
Updated
2026-02-12
·
CVE-2023-52999
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to the fixed version
Description
A use-after-free (UaF) issue has been identified in the Linux kernel's netns ops registration error path. When
net assign generic() fails, the error path in ops init() attempts to clear the gen pointer slot, but the gen pointer itself has not been modified yet, leading to an out-of-bounds error. This issue was discovered through code inspection and verified with explicit error injection on a kasan-enabled kernel.Recommendations
For Linux kernel versions prior to the fixed version, apply the patch that skips the gen pointer de-reference in the error path to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable
ops init() function until a patch is available.Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat
Red Os