CVE-2023-53432

Source
https://cve.org/CVERecord?id=CVE-2023-53432
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53432.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53432
Downstream
Related
Published
2025-09-18T16:04:12.446Z
Modified
2026-05-28T03:53:36.108004643Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
firewire: net: fix use after free in fwnet_finish_incoming_packet()
Details

In the Linux kernel, the following vulnerability has been resolved:

firewire: net: fix use after free in fwnetfinishincoming_packet()

The netif_rx() function frees the skb so we can't dereference it to save the skb->len.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53432.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c76acec6d55107b652a37c90b36c00bc8b04dabb
Fixed
2ea70379e4f4efa95c9daa7f3f9bdd4d40aec927
Fixed
9040adc38cf6bfbb77034d558ac2c52f70d840ac
Fixed
9860921ab4521252dc39bb21b9c936bd09a00982
Fixed
3ff256751a2853e1ffaa36958ff933ccc98c6cb5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53432.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.31
Fixed
5.15.128
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.47
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.4.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53432.json"