CVE-2023-2019
Linux Kernel ≤ 6.0
Raw vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HSummary
CVE-2023-2019 is a medium-severity Improper Update of Reference Count (CWE-911) vulnerability in Linux Linux Kernel. Its CVSS base score is 4.4 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 27th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-33547
Vulnerability Data
A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events. This issue results from the improper management of a reference count. This may allow an attacker to create a denial of service condition on…
more
the system.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent reference-count coding errors via reviews, static analysis, and testing.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect reference-count defects before release, providing partial mitigation.
Secure development lifecycle practices can include reference-counting rules and automated checks that reduce the likelihood of improper updates.
Application security requirements can mandate correct resource-lifetime management, indirectly addressing reference-count errors.
Secure system architecture principles encourage explicit resource-ownership models that mitigate reference-count misuse.
Secure coding standards directly prescribe correct increment/decrement patterns, covering most instances of this weakness.
Change-management processes may catch reference-count issues introduced by modifications, but do not address the root coding flaw.