Back

MEDIUM

Kernel: xfrm: null pointer dereference in xfrm_update_ae_params()

Published Jul 25, 2023

Description

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

Affected products

Remediation

No remediation recorded yet.

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jul 25, 2023
Updated Nov 7, 2025
Reserved Jul 19, 2023

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 21, 2023
Bugzilla 2218943

ENISA EUVD

Assigner redhat
Published Jul 25, 2023
Updated Nov 7, 2025

GitHub

No data