CVE-2023-54273

Linux Kernel 6.2-6.3.4 - Use-After-Free in xfrm Direction Check

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix leak of dev tracker At the stage of direction checks, the netdev reference tracker is already initialized, but released with wrong *_put() call.

Scores

EPSS 0.0016
EPSS Percentile 5.8%

Details

Status published
Products (7)
linux/Kernel 6.2.0 - 6.3.4linux
Linux/Linux < 6.2
Linux/Linux 6.2
Linux/Linux 6.3.4 - 6.3.*
Linux/Linux 6.4
Linux/Linux 919e43fad5163a8ceb39826ecdee897a9f799351 - 7d16c515059b3746f2d6a24a74c3ba786a68c2a1
Linux/Linux 919e43fad5163a8ceb39826ecdee897a9f799351 - ec8f32ad9a65a8cbb465b69e154aaec9d2fe45c4
Published Dec 30, 2025
Tracked Since Feb 18, 2026