CVE-2023-53432Use After Free in Linux

CWE-416Use After Free5 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 97.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: firewire: net: fix use after free in fwnet_finish_incoming_packet() The netif_rx() function frees the skb so we can't dereference it to save the skb->len.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel5.166.1.47+2
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linuxc76acec6d55107b652a37c90b36c00bc8b04dabb2ea70379e4f4efa95c9daa7f3f9bdd4d40aec927+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vgfh-vgxv-c838: In the Linux kernel, the following vulnerability has been resolved: firewire: net: fix use after free in fwnet_finish_incoming_packet() The netif_rx2025-09-18
OSV
CVE-2023-53432: In the Linux kernel, the following vulnerability has been resolved: firewire: net: fix use after free in fwnet_finish_incoming_packet() The netif_rx()2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: firewire: net: fix use after free in fwnet_finish_incoming_packet()2025-09-18
Debian
CVE-2023-53432: linux - In the Linux kernel, the following vulnerability has been resolved: firewire: n...2023
CVE-2023-53432 — Use After Free in Linux | cvebase