PT-2025-13345 · Linux+3 · Linux Kernel+3

Published

2024-04-30

·

Updated

2026-02-12

·

CVE-2023-52999

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A use-after-free (UaF) issue has been identified in the Linux kernel's netns ops registration error path. When net assign generic() fails, the error path in ops init() attempts to clear the gen pointer slot, but the gen pointer itself has not been modified yet, leading to an out-of-bounds error. This issue was discovered through code inspection and verified with explicit error injection on a kasan-enabled kernel.
Recommendations For Linux kernel versions prior to the fixed version, apply the patch that skips the gen pointer de-reference in the error path to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable ops init() function until a patch is available.

Exploit

Fix

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-06318
CVE-2023-52999
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2026:0473-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Red Os