CVE-2023-53401NULL Pointer Dereference in Linux

Severity
4.7MEDIUMNVD
EPSS
0.0%
top 97.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() KCSAN found an issue in obj_stock_flush_required(): stock->cached_objcg can be reset between the check and dereference: BUG: KCSAN: data-race in drain_all_stock / drain_obj_stock write to 0xffff888237c2a2f8 of 8 bytes by task 19625 on cpu 0: drain_obj_stock+0x408/0x4e0 mm/memcontrol.c:3306 refill_obj_stock+0x9c/0x1e0 mm/memcontrol.c:3340 obj_cgroup_unchar

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-67c3-x939-573c: In the Linux kernel, the following vulnerability has been resolved: mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() KCSAN fou2025-09-18
OSV
CVE-2023-53401: In the Linux kernel, the following vulnerability has been resolved: mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() KCSAN found2025-09-18

📋Vendor Advisories

3
Red Hat
kernel: mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()2025-09-18
Microsoft
mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()2025-09-09
Debian
CVE-2023-53401: linux - In the Linux kernel, the following vulnerability has been resolved: mm: kmem: f...2023
CVE-2023-53401 — NULL Pointer Dereference in Linux | cvebase