PT-2025-40187 · Linux+2 · Linux Kernel+2

Published

2023-08-19

·

Updated

2025-11-19

·

CVE-2023-53480

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to the registration of ksets. Specifically, a null pointer dereference can occur in the kset register() function if the kset->kobj.ktype is not initialized. This happens when registering a kset without first initializing the kobj.ktype member. The issue leads to a kernel NULL pointer dereference, potentially causing system instability. The kobject get ownership() and kobject add internal() functions are involved in the call trace.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06065
CVE-2023-53480
OESA-2025-2468
OESA-2025-2469
SUSE-SU-2025:03600-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:3761-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1

Affected Products

Astra Linux
Linux Kernel
Suse