PT-2025-54035 · Linux+2 · Linux Kernel+2

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2023-54206

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.3.0-rc4+
Description The Linux kernel contained a flaw in the networking scheduler's flower component related to filter IDR initialization. A commit moved the IDR initialization too early, potentially allowing concurrent access to a filter that was still being initialized, leading to an inconsistent state and a possible NULL pointer dereference. This issue could result in a general protection fault, as indicated by KASAN reports. The vulnerability occurs during the dumping of keys, specifically within the fl dump key function.
Recommendations Update to a version newer than 6.3.0-rc4+ to address this issue.

Exploit

Related Identifiers

CVE-2023-54206
RHSA-2023:6583
RHSA-2023:7077

Affected Products

Centos
Linux Kernel
Red Hat