PT-2025-40187 · Linux+2 · Linux Kernel+2
Published
2023-08-19
·
Updated
2025-11-19
·
CVE-2023-53480
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel related to the registration of ksets. Specifically, a null pointer dereference can occur in the
kset register() function if the kset->kobj.ktype is not initialized. This happens when registering a kset without first initializing the kobj.ktype member. The issue leads to a kernel NULL pointer dereference, potentially causing system instability. The kobject get ownership() and kobject add internal() functions are involved in the call trace.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse