CVE-2023-52653 is a Linux kernel memory-leak flaw in the SUNRPC GSS/Kerberos context-import path. When gss_import_v2_context fails, memory allocated through kmemdup for ctx->mech_used.data is not released before gss_krb5_import_sec_context frees the context. The defect, present since kernel 2.6.35 in net/sunrpc/auth_gss/gss_krb5_mech.c, can cause an availability impact for local, low-privileged users; Red Hat rates it CVSS 3.1 5.5.
The upstream fix is included in stable Linux kernels 6.6.23, 6.7.11, 6.8.2, and 6.9-rc1, and administrators should deploy a current stable kernel. Red Hat released fixes for RHEL 8 kernel and kernel-rt packages in August 2024 and for the RHEL 9.4 Extended Update Support kernel in April 2025; RHEL 9 remains affected, with its kernel-rt update deferred.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101 for the Red Hat Enterprise Linux 8 kernel and RHSA-2024:5102 for the RHEL 8 kernel-rt, fixing CVE-2023-52653 in both packages.
Red Hat published its CVE-2023-52653 record, documenting a low-severity Linux kernel SUNRPC memory leak. Red Hat assigned a CVSS v3.1 score of 5.5, with local low-privilege access required and availability as the only impacted security property.
Red Hat released RHSA-2025:3510, fixing CVE-2023-52653 for the Red Hat Enterprise Linux 9.4 Extended Update Support kernel.
The issue was fixed in Linux kernel versions 6.6.23, 6.7.11, 6.8.2, and 6.9-rc1. The remediation replaces the final gss_import_v2_context call with gss_krb5_import_ctx_v2 to ensure the allocated memory is freed while preserving return behavior.
The SUNRPC GSS/Kerberos context-import memory leak was introduced in Linux kernel 2.6.35 by commit 47d848077629. On an error path, the context cleanup did not free memory allocated for ctx->mech_used.data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.