CVE-2023-53309
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53309 affects the Linux kernel, specifically the drm/radeon component. The vulnerability was discovered and disclosed in September 2025. The issue involves an integer overflow vulnerability in the radeoncsparserinit function where if size is 0x40000000, multiplication with sizeof(uint32t) causes an integer overflow, resulting in size becoming zero and leading to uninitialized memory references (NVD).

Technical details

The vulnerability stems from an integer overflow condition in the radeoncsparserinit function of the Linux kernel's DRM (Direct Rendering Manager) Radeon driver. When the size parameter is set to 0x40000000, multiplication with sizeof(uint32t) causes an integer overflow, resulting in a zero value. This leads to subsequent uninitialized memory references in the code execution path (NVD).

Impact

The vulnerability could lead to uninitialized memory being referenced, potentially causing system instability or information disclosure. Multiple Linux distributions and versions are affected, including Ubuntu 22.04 LTS, 20.04 LTS, and various kernel packages across different platforms (Ubuntu).

Mitigation and workarounds

Fixes have been released for various affected Linux distributions. Ubuntu has released patches for multiple kernel versions: linux 5.15.0-88.98 for 22.04 LTS and linux 5.4.0-169.187 for 20.04 LTS. Other affected packages such as linux-aws, linux-azure, and linux-gcp have also received corresponding updates (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-devel
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-trace
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management