CVE-2023-53987

NONE EPSS 6.3%
Published Dec 24, 20256mo ago · Modified Jun 17, 20262w ago
Find Similar
Published Dec 24, 2025 6mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ping: Fix potentail NULL deref for /proc/net/icmp. After commit dbca1596bbb0 ("ping: convert to RCU lookups, get rid of rwlock"), we use RCU for ping sockets, but we should use spinlock for /proc/net/icmp to avoid a potential NULL deref mentioned in the previous patch. Let's go back to using spinlock there. Note we can convert ping sockets to use hlist instead of hlist_nulls because we do not use SLAB_TYPESAFE_BY_RCU for ping sockets.

Threat Intelligence

EPSS Exploit Probability
6.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

References 3

  • git.kernel.org https://git.kernel.org/stable/c/176cbb6da28f36506cc60a4bec4ab8df0c16713a
  • git.kernel.org https://git.kernel.org/stable/c/5a08a32e624908890aa0a2eb442bb6a7669891a8
  • git.kernel.org https://git.kernel.org/stable/c/ab5fb73ffa01072b4d8031cc05801fa1cb653bee

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.