cbcvebase.
CVE-2023-53005
published 2025-03-27

CVE-2023-53005: In the Linux kernel, the following vulnerability has been resolved: trace_events_hist: add check for return value of 'create_hist_field' Function…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.7th percentile
In the Linux kernel, the following vulnerability has been resolved: trace_events_hist: add check for return value of 'create_hist_field' Function 'create_hist_field' is called recursively at trace_events_hist.c:1954 and can return NULL-value that's why we have to check it to avoid null pointer dereference. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= 30350d65ac5676c6d08d4fc935bc9a9cb0fd4ed3 < d2d1ada58e7cc100b8d7d6b082d19321ba4a700ad2d1ada58e7cc100b8d7d6b082d19321ba4a700a
linuxlinux>= 30350d65ac5676c6d08d4fc935bc9a9cb0fd4ed3 < 31b2414abeaa6de0490e85164badc6dcb1bb8ec931b2414abeaa6de0490e85164badc6dcb1bb8ec9
linuxlinux>= 30350d65ac5676c6d08d4fc935bc9a9cb0fd4ed3 < 886aa449235f478e262bbd5dcdee6ed6bc202949886aa449235f478e262bbd5dcdee6ed6bc202949
linuxlinux>= 30350d65ac5676c6d08d4fc935bc9a9cb0fd4ed3 < 592ba7116fa620425725ff0972691f352ba3caf6592ba7116fa620425725ff0972691f352ba3caf6
linuxlinux>= 30350d65ac5676c6d08d4fc935bc9a9cb0fd4ed3 < b4e7e81b4fdfcf457daee6b7a61769f62198d840b4e7e81b4fdfcf457daee6b7a61769f62198d840
linuxlinux>= 30350d65ac5676c6d08d4fc935bc9a9cb0fd4ed3 < 8b152e9150d07a885f95e1fd401fc81af202d9a48b152e9150d07a885f95e1fd401fc81af202d9a4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 4.17 < 4.19.2724.19.272
linuxlinux_kernel>= 4.20 < 5.4.2315.4.231
linuxlinux_kernel>= 5.11 < 5.15.915.15.91
linuxlinux_kernel>= 5.16 < 6.1.96.1.9
linuxlinux_kernel>= 5.5 < 5.10.1665.10.166

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.