PT-2025-38050 · Linux+2 · Linux Kernel+2

Published

2023-01-01

·

Updated

2026-04-20

·

CVE-2023-53332

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to inter-processor interrupts (IPIs). Specifically, a NULL pointer dereference can occur in the irq data get affinity mask() function when ipi send {mask|single}() is called with an invalid interrupt number. This can lead to a kernel oops as the NULL pointer is dereferenced during verification in the ipi send verify() function. The issue was discovered by the Linux Verification Center using the SVACE static analysis tool.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-71888
BDU:2026-05894
CVE-2023-53332
OESA-2025-2348
OESA-2025-2349
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:3761-1

Affected Products

Debian
Linux Kernel
Suse