CVE-2023-53332
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability has been identified in the Linux kernel related to a NULL pointer dereference in the irq_data_get_affinity_mask() function. The issue was discovered by the Linux Verification Center using the SVACE static analysis tool. The vulnerability was assigned CVE-2023-53332 and was published on September 16, 2025 (NVD).

Technical details

The vulnerability occurs when ipi_send_{mask|single}() is called with an invalid interrupt number, causing all local variables to be NULL. While ipi_send_verify() function verifies its 'data' parameter, a missing NULL pointer check leads to a kernel oops when the NULL pointer is dereferenced in irq_data_get_affinity_mask() (NVD).

Impact

When exploited, this vulnerability can cause a kernel oops, potentially leading to system instability or denial of service conditions (NVD).

Mitigation and workarounds

The vulnerability has been resolved by adding a missing NULL pointer check in the ipi_send_verify() function (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-oem-6.14
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-core
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • linux-aws-fips
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management