PT-2025-54035 · Linux+2 · Linux Kernel+2
CVE-2023-54206
·
Published
2025-12-30
·
Updated
2025-12-31
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.3.0-rc4+
Description
The Linux kernel contained a flaw in the networking scheduler's flower component related to filter IDR initialization. A commit moved the IDR initialization too early, potentially allowing concurrent access to a filter that was still being initialized, leading to an inconsistent state and a possible NULL pointer dereference. This issue could result in a general protection fault, as indicated by KASAN reports. The vulnerability occurs during the dumping of keys, specifically within the
fl dump key function.Recommendations
Update to a version newer than 6.3.0-rc4+ to address this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Linux Kernel
Red Hat