PT-2025-54035 · Linux+2 · Linux Kernel+2

CVE-2023-54206

·

Published

2025-12-30

·

Updated

2025-12-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.3.0-rc4+
Description The Linux kernel contained a flaw in the networking scheduler's flower component related to filter IDR initialization. A commit moved the IDR initialization too early, potentially allowing concurrent access to a filter that was still being initialized, leading to an inconsistent state and a possible NULL pointer dereference. This issue could result in a general protection fault, as indicated by KASAN reports. The vulnerability occurs during the dumping of keys, specifically within the fl dump key function.
Recommendations Update to a version newer than 6.3.0-rc4+ to address this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-54206
RHSA-2023:6583
RHSA-2023:7077

Affected Products

Centos
Linux Kernel
Red Hat