CVE-2023-53432

HIGH

Linux kernel < 5.15.128 - Use-After-Free in fwnet_finish_incoming_packet

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: firewire: net: fix use after free in fwnet_finish_incoming_packet() The netif_rx() function frees the skb so we can't dereference it to save the skb->len.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (11)
Linux/Linux < 2.6.31
Linux/Linux 2.6.31
Linux/Linux 5.15.128 - 5.15.*
Linux/Linux 6.1.47 - 6.1.*
Linux/Linux 6.4.12 - 6.4.*
Linux/Linux 6.5
Linux/Linux c76acec6d55107b652a37c90b36c00bc8b04dabb - 2ea70379e4f4efa95c9daa7f3f9bdd4d40aec927
Linux/Linux c76acec6d55107b652a37c90b36c00bc8b04dabb - 3ff256751a2853e1ffaa36958ff933ccc98c6cb5
Linux/Linux c76acec6d55107b652a37c90b36c00bc8b04dabb - 9040adc38cf6bfbb77034d558ac2c52f70d840ac
Linux/Linux c76acec6d55107b652a37c90b36c00bc8b04dabb - 9860921ab4521252dc39bb21b9c936bd09a00982
... and 1 more
Published Sep 18, 2025
Tracked Since Feb 18, 2026