CVE-2023-53282Use After Free in Linux

CWE-416Use After Free5 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 97.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free KFENCE violation during sysfs firmware write During the sysfs firmware write process, a use-after-free read warning is logged from the lpfc_wr_object() routine: BUG: KFENCE: use-after-free read in lpfc_wr_object+0x235/0x310 [lpfc] Use-after-free read at 0x0000000000cf164d (in kfence-#111): lpfc_wr_object+0x235/0x310 [lpfc] lpfc_write_firmware.cold+0x206/0x30d [lpfc] lpfc_sli4_request_firmware_up

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel5.166.1.16+2
Debianlinux/linux_kernel< 6.1.20-1+2
CVEListV5linux/linux52d5244096017bbd11164479116baceaede342b051ab4eb1a25e73c7fc2ad9026520c4d8369c93cc+4
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7wcq-h796-g66p: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free KFENCE violation during sysfs firmware write Duri2025-09-16
OSV
CVE-2023-53282: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free KFENCE violation during sysfs firmware write During2025-09-16

📋Vendor Advisories

2
Red Hat
kernel: scsi: lpfc: Fix use-after-free KFENCE violation during sysfs firmware write2025-09-16
Debian
CVE-2023-53282: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc:...2023
CVE-2023-53282 — Use After Free in Linux | cvebase