Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53147

20
FAUCET Score

CVE-2023-53147 is a Null Pointer Dereference vulnerability in the Linux kernel's xfrm subsystem, specifically within the xfrm_update_ae_params function. This flaw allows a local, unprivileged attacker to trigger a kernel crash, leading to a denial-of-service condition. Rated with a CVSS score of 5.5 (Medium), the vulnerability requires local access and low privileges, but does not necessitate user interaction. Its impact is limited to availability, as it can cause system instability and crashes. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.39, < 4.14.324CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.293CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.255CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.192CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.128CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 27th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-513.5.1.el8_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: kernel-0:4.18.0-477.43.1.el8_8
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53147Moderate

kernel: xfrm: add NULL check in xfrm_update_ae_params

Sep 15, 2025

References

git.kernel.org / stable/c/00374d9b6d9f932802b55181be9831aa948e5b7c
Patch
git.kernel.org / stable/c/075448a2eb753f813fe873cfa52853e9fef8eedb
Patch
git.kernel.org / stable/c/44f69c96f8a147413c23c68cda4d6fb5e23137cd
Patch
git.kernel.org / stable/c/53df4be4f5221e90dc7aa9ce745a9a21bb7024f4
Patch
git.kernel.org / stable/c/8046beb890ebc83c5820188c650073e1c6066e67
Patch
git.kernel.org / stable/c/87b655f4936b6fc01f3658aa88a22c923b379ebd
Patch
git.kernel.org / stable/c/bd30aa9c7febb6e709670cd5154194189ca3b7b5
Patch
git.kernel.org / stable/c/ed1cba039309c80b49719fcff3e3d7cdddb73d96
Patch