Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52609

16
FAUCET Score

CVE-2023-52609 is a race condition in the Linux kernel's Binder inter-process communication mechanism, affecting Debian and other Linux distributions. This vulnerability occurs when a task attempts to pin a remote address space while the remote task is exiting, leading to a deadlock where cleanup work is delayed indefinitely. With a CVSS score of 4.7 (Medium), it has a local attack vector, high attack complexity, and can lead to a denial of service (availability impact). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.29, < 4.19.306CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.268CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.209CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.148CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.75CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 43rd percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2023-52609Low

kernel: binder: fix race between mmput() and do_exit()

Mar 18, 2024

References

git.kernel.org / stable/c/252a2a5569eb9f8d16428872cc24dea1ac0bb097
Mailing ListPatch
git.kernel.org / stable/c/6696f76c32ff67fec26823fc2df46498e70d9bf3
Mailing ListPatch
git.kernel.org / stable/c/67f16bf2cc1698fd50e01ee8a2becc5a8e6d3a3e
Mailing ListPatch
git.kernel.org / stable/c/77d210e8db4d61d43b2d16df66b1ec46fad2ee01
Mailing ListPatch
git.kernel.org / stable/c/7e7a0d86542b0ea903006d3f42f33c4f7ead6918
Mailing ListPatch
git.kernel.org / stable/c/95b1d336b0642198b56836b89908d07b9a0c9608
Mailing ListPatch
git.kernel.org / stable/c/98fee5bee97ad47b527a997d5786410430d1f0e9
Mailing ListPatch
git.kernel.org / stable/c/9a9ab0d963621d9d12199df9817e66982582d5a5
Mailing ListPatch
lists.debian.org / debian-lts-announce/2024/06/msg00016.html
Mailing List
lists.debian.org / debian-lts-announce/2024/06/msg00020.html
Mailing List