PT-2025-37700 · Linux+3 · Linux Kernel+3

Published

2023-01-01

·

Updated

2026-03-14

·

CVE-2023-53259

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.0-rc4
Description The Linux kernel contains a flaw in the VMCI subsystem where a call to get user pages fast() in vmci host setup notify() can return a NULL value for context->notify page, leading to a general protection fault (GPF). The issue occurs due to a missing check for a NULL context->notify page after the call to get user pages fast().
Recommendations Update to a version of the Linux kernel that addresses this issue.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-05886
CVE-2023-53259
DLA-4327-1
OESA-2025-2406
OESA-2025-2407
OESA-2025-2408
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Debian
Linux Kernel
Suse