CVE-2023-53559

Updated: 2025-11-03 02:44:02.718539

Description:

In the Linux kernel, the following vulnerability has been resolved: ip_vti: fix potential slab-use-after-free in decode_session6 When ip_vti device is set to the qdisc of the sfb type, the cb field of the sent skb may be modified during enqueuing. Then, slab-use-after-free may occur when ip_vti device sends IPv6 packets. As commit f855691975bb ("xfrm6: Fix the nexthdr offset in _decode_session6.") showed, xfrm_decode_session was originally intended only for the receive path. IP6CB(skb)->nhoff is not set during transmission. Therefore, set the cb field in the skb to 0 before sending packets.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 6.7

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 6.7 MEDIUM Released CLSA-2025:1764151168 2025-11-27 10:33:27
CentOS 8.4 ELS kernel 4.18.0 6.7 MEDIUM Ignored 2025-11-05 05:01:28
CentOS 8.5 ELS kernel 4.18.0 6.7 MEDIUM Ignored 2025-11-05 05:01:30