Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53116

22
FAUCET Score

CVE-2023-53116 is a Use-After-Free (UAF) vulnerability in the Linux kernel's nvmet (NVM Express over Fabrics target) component. It arises when a target's queue_response() operation frees a request prematurely, leading to a UAF when percpu_ref_put() is subsequently called. This vulnerability has a high severity CVSS score of 7.8, indicating that a local attacker with low privileges could achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.8, < 4.14.311CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.279CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.238CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.176CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.104CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 32nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-362.8.1.el9_3
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53116Moderate

kernel: nvmet: avoid potential UAF in nvmet_req_complete()

May 2, 2025

References

git.kernel.org / stable/c/04c394208831d5e0d5cfee46722eb0f033cd4083
Patch
git.kernel.org / stable/c/6173a77b7e9d3e202bdb9897b23f2a8afe7bf286
Patch
git.kernel.org / stable/c/8ed9813871038b25a934b21ab76b5b7dbf44fc3a
Patch
git.kernel.org / stable/c/a6317235da8aa7cb97529ebc8121cc2a4c4c437a
Patch
git.kernel.org / stable/c/bcd535f07c58342302a2cd2bdd8894fe0872c8a9
Patch
git.kernel.org / stable/c/e5d99b29012bbf0e86929403209723b2806500c1
Patch
git.kernel.org / stable/c/f1d5888a5efe345b63c430b256e95acb0a475642
Patch
git.kernel.org / stable/c/fafcb4b26393870c45462f9af6a48e581dbbcf7e
Patch