cbcvebase.
CVE-2023-53047
published 2025-05-02

CVE-2023-53047: In the Linux kernel, the following vulnerability has been resolved: tee: amdtee: fix race condition in amdtee_open_session There is a potential race condition…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.14%
3.8th percentile
In the Linux kernel, the following vulnerability has been resolved: tee: amdtee: fix race condition in amdtee_open_session There is a potential race condition in amdtee_open_session that may lead to use-after-free. For instance, in amdtee_open_session() after sess->sess_mask is set, and before setting: sess->session_info[i] = session_info; if amdtee_close_session() closes this same session, then 'sess' data structure will be released, causing kernel panic when 'sess' is accessed within amdtee_open_session(). The solution is to set the bit sess->sess_mask as the last step in amdtee_open_session().

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 757cc3e9ff1d72d014096399d6e2bf03974d9da1 < f632a90f8e39db39b322107b9a8d438b826a7f4ff632a90f8e39db39b322107b9a8d438b826a7f4f
linuxlinux>= 757cc3e9ff1d72d014096399d6e2bf03974d9da1 < 02b296978a2137d7128151c542e84dc96400bc0002b296978a2137d7128151c542e84dc96400bc00
linuxlinux>= 757cc3e9ff1d72d014096399d6e2bf03974d9da1 < a63cce9393e4e7dbc5af82dc87e68cb321cb1a78a63cce9393e4e7dbc5af82dc87e68cb321cb1a78
linuxlinux>= 757cc3e9ff1d72d014096399d6e2bf03974d9da1 < b3ef9e6fe09f1a132af28c623edcf4d4f39d9f35b3ef9e6fe09f1a132af28c623edcf4d4f39d9f35
linuxlinux>= 757cc3e9ff1d72d014096399d6e2bf03974d9da1 < f8502fba45bd30e1a6a354d9d898bc99d1a11e6df8502fba45bd30e1a6a354d9d898bc99d1a11e6d
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.11 < 5.15.1055.15.105
linuxlinux_kernel>= 5.16 < 6.1.226.1.22
linuxlinux_kernel>= 5.6 < 5.10.1775.10.177
linuxlinux_kernel>= 6.2 < 6.2.96.2.9

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.