CVE-2023-52889 is a null pointer dereference vulnerability in the Linux kernel's AppArmor security module. Specifically, it occurs when an ICMP raw socket is being created and simultaneously receives ICMP packets with a security mark (secmark) set, before the socket's security label context is fully initialized. This can lead to a kernel panic, effectively causing a denial of service (DoS) on affected Linux systems. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (denial of service). There is no confidentiality or integrity impact. Currently, there is no public exploit code available, nor is there evidence of active exploitation. The vulnerability has not garnered significant community discussion or media coverage, and it is not listed in CISA's Known Exploited Vulnerabilities Catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.20, < 5.4.282CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.224CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.165CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.103CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025CVE-2023-52889
Oct 8, 2024kernel: apparmor: Fix null pointer deref when receiving skb during sock creation
Aug 17, 2024apparmor: Fix null pointer deref when receiving skb during sock creation
Aug 13, 2024