PT-2025-37669 · Linux+3 · Linux Kernel+3

Published

2023-05-03

·

Updated

2025-09-29

·

CVE-2023-53228

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to redundant scheduler job cleanup when command submission is aborted. Specifically, after command submission fails due to userptr invalidation in amdgpu cs submit, legacy code performs unnecessary cleanup of the scheduler job. This can lead to a double-free condition and a subsequent NULL pointer dereference.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-04618
CVE-2023-53228
RHSA-2024:2394
RHSA-2024_2394

Affected Products

Astra Linux
Linux Kernel
Red Hat
Amdgpu Cs Submit