Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-52828

17
FAUCET Score

CVE-2023-52828 is a vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) subsystem. It arises when a BPF program uses a "bpf_throw" kfunc or a subprogram that always throws, especially when such a call is the final instruction. This can lead to unreliable stack unwinding and a kernel panic because the return address falls outside the program's recognized boundaries. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity. A successful exploit could lead to a denial of service (kernel panic), impacting system availability. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness and attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.10.202CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.140CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.64CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.5.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.6, < 6.6.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 68th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-52828Low

kernel: bpf: Detect IP == ksym.end as part of BPF program

May 21, 2024

References

git.kernel.org / stable/c/327b92e8cb527ae097961ffd1610c720481947f5
Patch
git.kernel.org / stable/c/6058e4829696412457729a00734969acc6fd1d18
Patch
git.kernel.org / stable/c/66d9111f3517f85ef2af0337ece02683ce0faf21
Patch
git.kernel.org / stable/c/821a7e4143af115b840ec199eb179537e18af922
Patch
git.kernel.org / stable/c/aa42a7cb92647786719fe9608685da345883878f
Patch
git.kernel.org / stable/c/cf353904a82873e952633fcac4385c2fcd3a46e1
Patch