VYPR
Unrated severityNVD Advisory· Published Jul 25, 2023· Updated Nov 7, 2025

Kernel: xfrm: null pointer dereference in xfrm_update_ae_params()

CVE-2023-3772

Description

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

Affected products

472

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.