Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53518

20
FAUCET Score

CVE-2023-53518 is a memory leak vulnerability in the Linux kernel's devfreq module, specifically within the devfreq_dev_release() function, affecting various Linux kernel versions. With a CVSS score of 5.5 (Medium), it can lead to a denial of service (A:H) through local access (AV:L) with low privileges (PR:L), requiring no user interaction (UI:N). There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.7, < 4.14.326CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.295CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.257CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.195CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.132CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 24th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53518Low

kernel: Linux kernel: Memory leak in PM / devfreq can lead to denial of service

Oct 1, 2025

References

git.kernel.org / stable/c/111bafa210ae546bee7644be730c42df9c35b66e
Patch
git.kernel.org / stable/c/1640e9c72173911ad0fddb05012c01eafe082c4e
Patch
git.kernel.org / stable/c/29811f4b8255d4238cf326f3bb7129784766beab
Patch
git.kernel.org / stable/c/3354c401c68d70567d1ef25d12f4e22a7813a3c6
Patch
git.kernel.org / stable/c/5693d077595de721f9ddbf9d37f40e5409707dfe
Patch
git.kernel.org / stable/c/64e6e0dc2d578c0a9e31cb4edd719f0a3ed98f6d
Patch
git.kernel.org / stable/c/7462483446cb9986568ad7adae746ce5f18d2968
Patch
git.kernel.org / stable/c/8918025feb2f5f7c73f2495c158f22997e25cb02
Patch
git.kernel.org / stable/c/ab192e5e5d3b48415909a8408acfd007a607bcc0
Patch