Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-54142

11
FAUCET Score

CVE-2023-54142 addresses a use-after-free vulnerability in the Linux kernel's GTP (GPRS Tunnelling Protocol) encapsulation module. This flaw, discovered by syzkaller, occurs because the 'release_sock()' function is incorrectly called after the socket's last reference count is released, leading to attempts to access freed memory. While specific affected products are not detailed beyond the Linux kernel, the issue impacts systems utilizing GTP. The severity of this vulnerability is moderate, with a FAUCET Risk Score of 7/100. A successful exploit could lead to system instability, denial of service, or potentially arbitrary code execution, though the attack vector and complexity are not explicitly defined. The vulnerability is not currently listed on the CISA KEV catalog, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite the lack of public exploits, the vulnerability has garnered significant community attention with 6 mentions and 6 media articles, primarily from SUSE security advisories detailing live patch updates for their Linux Enterprise products. This indicates active patching efforts by vendors, suggesting awareness of the potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.14.135, < 4.14.322CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.19.61, < 4.19.291CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.1.20, < 5.2CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.2.3, < 5.3CPE match
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

Remediation

Vendor Advisories (1)

redhatCVE-2023-54142

kernel: gtp: Fix use-after-free in __gtp_encap_destroy()

Dec 24, 2025

References

git.kernel.org / stable/c/17d6b6354f0025b7c10a56da783fd0cbb3819c5d
git.kernel.org / stable/c/58fa341327fdb4bdf92597fd8796a9abc8d20ea3
git.kernel.org / stable/c/9c9662e2512b5e4ee7b03108802c5222e0fa77a4
git.kernel.org / stable/c/bccc7ace12e69dee4684a3bb4b69737972e570d6
git.kernel.org / stable/c/ce3aee7114c575fab32a5e9e939d4bbb3dcca79f
git.kernel.org / stable/c/d38039697184aacff1cf576e14ef583112fdefef
git.kernel.org / stable/c/dae6095bdb24f537b4798ffd9201515b97bac94e
git.kernel.org / stable/c/e5aa6d829831a55a693dbaeb58f8d22ba7f2b3e6
git.kernel.org / stable/c/ebd6d2077a083329110695a996c00e8ca94bc640