PT-2025-38374 · Linux+6 · Linux Kernel+6

Published

2023-06-26

·

Updated

2025-12-01

·

CVE-2023-53395

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.0.0-dev-th500-6.0.y-1+bcf8c46459e407-generic-64k
Description The Linux kernel contains a flaw within the ACPICA component related to the handling of ASL Timer instructions. Specifically, the issue arises when interpreting ASL timer instructions by the ACPI interpreter, leading to an error. The addition of the AML NO OPERAND RESOLVE flag to the ASL Timer instruction opcode resolves this issue. Additionally, a use-after-free condition was identified in acpica/dswexec.c resulting in an out-of-bounds array access.
Recommendations Update to Linux kernel version 6.0.0-dev-th500-6.0.y-1+bcf8c46459e407-generic-64k or later.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2026-03338
CVE-2023-53395
OESA-2025-2407
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2025:03600-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:3761-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4135-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4188-1
SUSE-SU-2025:4315-1

Affected Products

Acpi
Acpica
Astra Linux
Linux Kernel
Red Hat
Suse
Dswexec.C