CVE-2023-53987
Published: Dec 24, 2025
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ping: Fix potentail NULL deref for /proc/net/icmp. After commit dbca1596bbb0 ("ping: convert to RCU lookups, get rid of rwlock"), we use RCU for ping sockets, but we should use spinlock for /proc/net/icmp to avoid a potential NULL deref mentioned in the previous patch. Let's go back to using spinlock there. Note we can convert ping sockets to use hlist instead of hlist_nulls because we do not use SLAB_TYPESAFE_BY_RCU for ping sockets.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected dbca1596bbb08318f5e3b3b99f8ca0a0d3830a65 - < 5a08a32e624908890aa0a2eb442bb6a7669891a8affected dbca1596bbb08318f5e3b3b99f8ca0a0d3830a65 - < 176cbb6da28f36506cc60a4bec4ab8df0c16713aaffected dbca1596bbb08318f5e3b3b99f8ca0a0d3830a65 - < ab5fb73ffa01072b4d8031cc05801fa1cb653beeaffected de3d723a3985f282a8c9e468d1e198616eb291c8affected 5.19.2 - < 5.20 |
Linux | Linux | affected 6.0unaffected 0 - < 6.0unaffected 6.1.24 - <= 6.1.*unaffected 6.2.11 - <= 6.2.*unaffected 6.3 - <= * |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now