PT-2025-40186 · Linux+3 · Linux Kernel+3

Published

2023-07-18

·

Updated

2025-11-19

·

CVE-2023-53479

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the CXL driver within the Linux kernel, specifically in the cxl parse cfmws() function. The problem occurs in the cxl decoder add() fail path, where memory pointed to by cxld is released via put device() and subsequently accessed. This results in a use-after-free condition detected by KASAN and KFENCE. The issue is addressed by using local variables within the dev err() function instead of referencing the released memory, and by changing the print format specifier to %pr.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-06103
CVE-2023-53479
RHSA-2023:6583
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse