cbcvebase.
CVE-2023-53084
published 2025-05-02

CVE-2023-53084: In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Remove another errant put in error path drm_gem_shmem_mmap() doesn't own…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
9.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/shmem-helper: Remove another errant put in error path drm_gem_shmem_mmap() doesn't own reference in error code path, resulting in the dma-buf shmem GEM object getting prematurely freed leading to a later use-after-free.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.9.5 < 5.105.10
linuxlinux>= f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a < 684c7372bbd6447c2e86a2a84e97a1478604d21f684c7372bbd6447c2e86a2a84e97a1478604d21f
linuxlinux>= f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a < 5cfb617967b05f8f27e862c97db1fabd8485f4db5cfb617967b05f8f27e862c97db1fabd8485f4db
linuxlinux>= f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a < dede8c14a37a7ac458f9add56154a074ed78e7cfdede8c14a37a7ac458f9add56154a074ed78e7cf
linuxlinux>= f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a < 77d26c824aa5a7e0681ef1d5b75fe538d746addc77d26c824aa5a7e0681ef1d5b75fe538d746addc
linuxlinux>= f49a51bfdc8ea717c97ccd4cc98b7e6daaa5553a < ee9adb7a45516cfa536ca92253d7ae59d56db9e4ee9adb7a45516cfa536ca92253d7ae59d56db9e4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.10.1 < 5.10.1765.10.176
linuxlinux_kernel>= 5.11 < 5.15.1045.15.104
linuxlinux_kernel>= 5.16 < 6.1.216.1.21
linuxlinux_kernel>= 5.9.5 < 5.105.10
linuxlinux_kernel>= 6.2 < 6.2.86.2.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.