#VU120825 Input validation error in Linux kernel - CVE-2023-54170
Published: December 30, 2025 / Updated: December 30, 2025
Vulnerability identifier: #VU120825
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-54170
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the construct_alloc_key() function in security/keys/request_key.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/00edfa6d4fe022942e2f2e6f3294ff13ef78b15c
- https://git.kernel.org/stable/c/0a6b0ca58685be34979236f83f2b322635b80b32
- https://git.kernel.org/stable/c/65bd66a794bfa059375ec834885bb610d75c0182
- https://git.kernel.org/stable/c/9aecfebea24fe6071ace5cc9fd6d690b87276bbb
- https://git.kernel.org/stable/c/d55901522f96082a43b9842d34867363c0cdbac5
- https://git.kernel.org/stable/c/e091bb55af9a930801f83df78195a908a76e1479
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.7