CVE-2023-53047: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: tee: amdtee: fix race condition in amdtee_open_session There is a potential race condition in amdtee_open_session that may lead to use-after-free. For instance, in amdtee_open_session() after sess->sess_mask is set, and before setting: sess->session_info[i] = session_info; if amdtee_close_session() closes this same session, then 'sess' data structure will be released, causing kernel panic when 'sess' is accessed within amdtee_open_session(). The solution is to set the bit sess->sess_mask as the last step in amdtee_open_session().
Affected products
- Linux Linux Kernel: from 5.6, before 5.10.177 (fixed in 5.10.177); from 5.11, before 5.15.105 (fixed in 5.15.105); from 5.16, before 6.1.22 (fixed in 6.1.22); from 6.2, before 6.2.9 (fixed in 6.2.9); version 6.3 only
Published 2025-05-02. Last modified 2026-08-04.