
Cloud Vulnerability DB
A community-led vulnerabilities database
A refcount bug in the Linux kernel's qrtr_recvmsg() function was identified and assigned CVE-2023-53445. The vulnerability was discovered by Syzbot and affects the net/qrtr subsystem. The issue was reported on September 18, 2025, and involves a reference counting issue that could lead to use-after-free conditions (NVD CVE).
The vulnerability occurs in a concurrent scenario between qrtr_recvmsg() and qrtr_endpoint_unregister() functions. The issue manifests when a refcount addition is attempted on a value of 0, potentially leading to a use-after-free condition. The bug specifically involves the interaction between qrtr_node_lookup and qrtr_node_acquire operations in the Linux kernel's QRTR (Qualcomm IPC Router) subsystem (NVD CVE).
The vulnerability could potentially lead to use-after-free conditions in the Linux kernel's QRTR subsystem, which might result in system instability or potential security implications (NVD CVE).
The fix involves using qrtr_node_lock to protect qrtr_node_lookup() implementation, improving the protection of node reference. This enhancement in the locking mechanism prevents the race condition that could lead to the reference counting issue (NVD CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."