CVE-2023-53705

Updated: 2025-10-29 15:02:25.735384

Description:

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.3 HIGH Already Fixed 2025-11-06 02:36:10 Already fixed in 5.14.0-284.1101.el9_2.tuxcare.7
CentOS 7 ELS kernel 3.10.0 7.3 HIGH Released CLSA-2026:1770040438 2026-02-10 13:43:29
CentOS 8.4 ELS kernel 4.18.0 7.3 HIGH Released CLSA-2025:1763731262 2025-11-21 21:28:48
CentOS 8.5 ELS kernel 4.18.0 7.3 HIGH Released CLSA-2025:1763734783 2025-11-21 21:28:49
CloudLinux 7 ELS kernel 3.10.0 7.3 HIGH Needs Triage 2026-01-19 08:30:55
Oracle Linux 7 ELS kernel 3.10.0 7.3 HIGH Released CLSA-2026:1770028389 2026-02-02 15:02:03
Oracle Linux 7 ELS kernel-uek 5.4.17 7.3 HIGH Already Fixed 2026-02-04 00:34:57
RHEL 7 ELS kernel 3.10.0 7.3 HIGH Released CLSA-2026:1770028764 2026-02-02 15:02:02