PT-2025-40176 · Linux+1 · Linux Kernel+1

Published

2023-08-23

·

Updated

2026-04-20

·

CVE-2023-53469

CVSS v2.0

3.8

Low

VectorAV:L/AC:H/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.5
Description The Linux kernel contains a flaw in the unix stream sendpage() function related to a null pointer dereference. This issue occurs when handling sockets in a specific loop scenario involving garbage collection, potentially leading to a use-after-free condition. The problem was addressed by locking the peer's receive queue within the unix stream sendpage() function.
Recommendations Update to version 6.5 or later.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2026-04558
CVE-2023-53469
ECHO-2E90-3164-8B50

Affected Products

Debian
Linux Kernel