CVE-2023-53023
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 27, 2025
Updated: Apr 1, 2025
CWE ID 416
Summary
CVE-2023-53023 is a use-after-free vulnerability in the Linux kernel's nfc (Near Field Communication) subsystem. Specifically, in the function local_cleanup(), a reference count error allows for the rx_pending buffer to be freed twice, leading to a use-after-free condition. This issue can occur when the nfc daemon is terminated after detaching an NFC device, resulting in the double free. The vulnerability was discovered using a modified version of syzkaller and can potentially lead to a kernel crash or arbitrary code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.