PT-2025-38044 · Linux+3 · Linux Kernel+3

Published

2025-09-16

·

Updated

2025-10-23

·

CVE-2023-53326

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to handling PowerPC (PPC) tasks with NULL pt regs. Specifically, the kernel attempts to copy Program Page Reference (PPR) data for tasks configured with PF KTHREAD or PF IO WORKER when the pt regs structure is NULL. This can lead to a kernel NULL pointer dereference during coredump generation, potentially resulting in a system crash. The issue occurs when the ppr get() function attempts to copy data from a PF IO WORKER task lacking a valid pt regs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-05893
CVE-2023-53326
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Powerpc
Suse