Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53330

18
FAUCET Score

CVE-2023-53330 is a memory leak vulnerability in the Linux kernel's CAIF subsystem, specifically within the cfctrl_linkup_request() function. This flaw occurs when an unknown linktype or a kzalloc failure prevents the proper release of a packet, leading to resource exhaustion. The vulnerability is rated Medium (CVSS 5.5), indicating that a local attacker with low privileges could exploit it without user interaction, potentially leading to a denial of service (high availability impact). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.35, < 4.14.303CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.270CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.163CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.87CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 22nd percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2023-53330

kernel: caif: fix memory leak in cfctrl_linkup_request()

Sep 16, 2025

References

git.kernel.org / stable/c/1dddeceb26002cfea4c375e92ac6498768dc7349
Patch
git.kernel.org / stable/c/33df9c5d5e2a18c70f5f5f3c2757d654c1b6ffa3
Patch
git.kernel.org / stable/c/3acf3783a84cbdf0c9f8cf2f32ee9c49af93a2da
Patch
git.kernel.org / stable/c/3ad47c8aa5648226184415e4a0cb1bf67ffbfd48
Patch
git.kernel.org / stable/c/84b2cc7b36b7f6957d307fb3d01603f93cb2d655
Patch
git.kernel.org / stable/c/badea57569db04b010e922e29a7aaf40a979a70b
Patch
git.kernel.org / stable/c/dc1bc903970bdf63ca40ab923d3ccb765da9a8d9
Patch
git.kernel.org / stable/c/fe69230f05897b3de758427b574fc98025dfc907
Patch