PT-2025-38374 · Linux+6 · Linux Kernel+6
Published
2023-06-26
·
Updated
2025-12-01
·
CVE-2023-53395
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.0.0-dev-th500-6.0.y-1+bcf8c46459e407-generic-64k
Description
The Linux kernel contains a flaw within the ACPICA component related to the handling of ASL Timer instructions. Specifically, the issue arises when interpreting ASL timer instructions by the ACPI interpreter, leading to an error. The addition of the
AML NO OPERAND RESOLVE flag to the ASL Timer instruction opcode resolves this issue. Additionally, a use-after-free condition was identified in acpica/dswexec.c resulting in an out-of-bounds array access.Recommendations
Update to Linux kernel version 6.0.0-dev-th500-6.0.y-1+bcf8c46459e407-generic-64k or later.
Exploit
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acpi
Acpica
Astra Linux
Linux Kernel
Red Hat
Suse
Dswexec.C