PT-2025-40186 · Linux+3 · Linux Kernel+3
Published
2023-07-18
·
Updated
2025-11-19
·
CVE-2023-53479
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in the CXL driver within the Linux kernel, specifically in the
cxl parse cfmws() function. The problem occurs in the cxl decoder add() fail path, where memory pointed to by cxld is released via put device() and subsequently accessed. This results in a use-after-free condition detected by KASAN and KFENCE. The issue is addressed by using local variables within the dev err() function instead of referencing the released memory, and by changing the print format specifier to %pr.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat
Suse