cbcvebase.
CVE-2023-53075
published 2025-05-02

CVE-2023-53075: In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix invalid address access in lookup_rec() when index is 0 KASAN reported follow…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix invalid address access in lookup_rec() when index is 0 KASAN reported follow problem: BUG: KASAN: use-after-free in lookup_rec Read of size 8 at addr ffff000199270ff0 by task modprobe CPU: 2 Comm: modprobe Call trace: kasan_report __asan_load8 lookup_rec ftrace_location arch_check_ftrace_location check_kprobe_address_safe register_kprobe When checking pg->records[pg->index - 1].ip in lookup_rec(), it can get a pg which is newly added to ftrace_pages_start in ftrace_process_locs(). Before the first pg->index++, index is 0 and accessing pg->records[-1].ip will cause this problem. Don't check the ip when pg->index is 0.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < 2de28e5ce34b22b73b833a21e2c45ae3aade39642de28e5ce34b22b73b833a21e2c45ae3aade3964
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < 7569ee04b0e3b32df79f64db3a7138573edad9bc7569ee04b0e3b32df79f64db3a7138573edad9bc
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < ac58b88ccbbb8e9fb83e137cee04a856b1ea6635ac58b88ccbbb8e9fb83e137cee04a856b1ea6635
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < 83c3b2f4e7c61367c7b24551f4c6eb94bbdda28383c3b2f4e7c61367c7b24551f4c6eb94bbdda283
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < 2a0d71fabfeb349216d33f001a6421b1768bd3a92a0d71fabfeb349216d33f001a6421b1768bd3a9
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < 4f84f31f63416b0f02fc146ffdc4ab32723eb7e84f84f31f63416b0f02fc146ffdc4ab32723eb7e8
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < f1bd8b7fd890d87d0dc4dedc6287ea34dd07c0b4f1bd8b7fd890d87d0dc4dedc6287ea34dd07c0b4
linuxlinux>= 9644302e3315e7e36495d230d5ac7125a316d33e < ee92fa443358f4fc0017c1d0d325c27b37802504ee92fa443358f4fc0017c1d0d325c27b37802504
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 3.5 < 4.14.3114.14.311
linuxlinux_kernel>= 4.15 < 4.19.2794.19.279
linuxlinux_kernel>= 4.20 < 5.4.2385.4.238
linuxlinux_kernel>= 5.11 < 5.15.1045.15.104
linuxlinux_kernel>= 5.16 < 6.1.216.1.21
linuxlinux_kernel>= 5.5 < 5.10.1765.10.176
linuxlinux_kernel>= 6.2 < 6.2.86.2.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.