Wiz Agents & Workflows are here

CVE-2023-53445
Linux Kernel vulnerability analysis and mitigation

Overview

A refcount bug in the Linux kernel's qrtr_recvmsg() function was identified and assigned CVE-2023-53445. The vulnerability was discovered by Syzbot and affects the net/qrtr subsystem. The issue was reported on September 18, 2025, and involves a reference counting issue that could lead to use-after-free conditions (NVD CVE).

Technical details

The vulnerability occurs in a concurrent scenario between qrtr_recvmsg() and qrtr_endpoint_unregister() functions. The issue manifests when a refcount addition is attempted on a value of 0, potentially leading to a use-after-free condition. The bug specifically involves the interaction between qrtr_node_lookup and qrtr_node_acquire operations in the Linux kernel's QRTR (Qualcomm IPC Router) subsystem (NVD CVE).

Impact

The vulnerability could potentially lead to use-after-free conditions in the Linux kernel's QRTR subsystem, which might result in system instability or potential security implications (NVD CVE).

Mitigation and workarounds

The fix involves using qrtr_node_lock to protect qrtr_node_lookup() implementation, improving the protection of node reference. This enhancement in the locking mechanism prevents the race condition that could lead to the reference counting issue (NVD CVE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23417N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-core
NoNoApr 02, 2026
CVE-2026-23415N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoNoApr 02, 2026
CVE-2026-23414N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-extra-matched
NoYesApr 02, 2026
CVE-2026-23413N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoYesApr 02, 2026
CVE-2026-23412N/AN/A
  • Linux KernelLinux Kernel
  • rv
NoYesApr 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management