cbcvebase.
CVE-2023-53147
published 2025-09-15

CVE-2023-53147: In the Linux kernel, the following vulnerability has been resolved: xfrm: add NULL check in xfrm_update_ae_params Normally, x->replay_esn and x->preplay_esn…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: xfrm: add NULL check in xfrm_update_ae_params Normally, x->replay_esn and x->preplay_esn should be allocated at xfrm_alloc_replay_state_esn(...) in xfrm_state_construct(...), hence the xfrm_update_ae_params(...) is okay to update them. However, the current implementation of xfrm_new_ae(...) allows a malicious user to directly dereference a NULL pointer and crash the kernel like below. BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 8253067 P4D 8253067 PUD 8e0e067 PMD 0 Oops: 0002 [#1] PREEMPT SMP KASAN NOPTI CPU: 0 PID: 98 Comm: poc.npd Not tainted 6.4.0-rc7-00072-gdad9774deaf1 #8 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.o4 RIP: 0010:memcpy_orig+0xad/0x140 Code: e8 4c 89 5f e0 48 8d 7f e0 73 d2 83 c2 20 48 29 d6 48 29 d7 83 fa 10 72 34 4c 8b 06 4c 8b 4e 08 c RSP: 0018:ffff888008f57658 EFLAGS: 00000202 RAX: 0000000000000000 RBX: ffff888008bd0000 RCX: ffffffff8238e571 RDX: 0000000000000018 RSI: ffff888007f64844 RDI: 0000000000000000 RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff888008f57818 R13: ffff888007f64aa4 R14: 0000000000000000 R15: 0000000000000000 FS: 00000000014013c0(0000) GS:ffff88806d600000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 00000000054d8000 CR4: 00000000000006f0 Call Trace: ? __die+0x1f/0x70 ? page_fault_oops+0x1e8/0x500 ? __pfx_is_prefetch.constprop.0+0x10/0x10 ? __pfx_page_fault_oops+0x10/0x10 ? _raw_spin_unlock_irqrestore+0x11/0x40 ? fixup_exception+0x36/0x460 ? _raw_spin_unlock_irqrestore+0x11/0x40 ? exc_page_fault+0x5e/0xc0 ? asm_exc_page_fault+0x26/0x30 ? xfrm_update_ae_params+0xd1/0x260 ? memcpy_orig+0xad/0x140 ? __pfx__raw_spin_lock_bh+0x10/0x10 xfrm_update_ae_params+0xe7/0x260 xfrm_new_ae+0x298/0x4e0 ? __pfx_xfrm_new_ae+0x10/0x10 ? __pfx_xfrm_new_ae+0x10/0x1

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < ed1cba039309c80b49719fcff3e3d7cdddb73d96ed1cba039309c80b49719fcff3e3d7cdddb73d96
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 44f69c96f8a147413c23c68cda4d6fb5e23137cd44f69c96f8a147413c23c68cda4d6fb5e23137cd
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 8046beb890ebc83c5820188c650073e1c6066e678046beb890ebc83c5820188c650073e1c6066e67
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < bd30aa9c7febb6e709670cd5154194189ca3b7b5bd30aa9c7febb6e709670cd5154194189ca3b7b5
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 075448a2eb753f813fe873cfa52853e9fef8eedb075448a2eb753f813fe873cfa52853e9fef8eedb
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 87b655f4936b6fc01f3658aa88a22c923b379ebd87b655f4936b6fc01f3658aa88a22c923b379ebd
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 53df4be4f5221e90dc7aa9ce745a9a21bb7024f453df4be4f5221e90dc7aa9ce745a9a21bb7024f4
linuxlinux>= d8647b79c3b7e223ac051439d165bc8e7bbb832f < 00374d9b6d9f932802b55181be9831aa948e5b7c00374d9b6d9f932802b55181be9831aa948e5b7c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 0 < 6.4.13-16.4.13-1
linuxlinux_kernel>= 2.6.39 < 4.14.3244.14.324
linuxlinux_kernel>= 4.15 < 4.19.2934.19.293
linuxlinux_kernel>= 4.20 < 5.4.2555.4.255
linuxlinux_kernel>= 5.11 < 5.15.1285.15.128
linuxlinux_kernel>= 5.16 < 6.1.476.1.47
linuxlinux_kernel>= 5.5 < 5.10.1925.10.192
linuxlinux_kernel>= 6.2 < 6.4.126.4.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.