PT-2025-37887 · Linux+3 · Linux Kernel+3

Published

2023-01-01

·

Updated

2026-03-14

·

CVE-2023-53282

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a use-after-free flaw within the lpfc wr object() routine during the sysfs firmware write process. The driver accesses data through a pointer (wr object) after the associated memory has been released back to the mailbox pool, leading to a potential kernel crash. The issue occurs when writing firmware via sysfs. The vulnerability is triggered during the lpfc write firmware.cold() and lpfc sli4 request firmware update() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-02190
CVE-2023-53282
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1
SUSE-SU-2025:4135-1
SUSE-SU-2025:4188-1
SUSE-SU-2025:4189-1
SUSE-SU-2025:4315-1

Affected Products

Astra Linux
Debian
Linux Kernel
Suse