PT-2023-8725 · Linux+2 · Linux Kernel+2

Syzbot

·

Published

2023-09-18

·

Updated

2025-09-29

·

CVE-2023-52577

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.0
Description The vulnerability is related to the dccp v4 err and dccp v6 err functions in the Linux kernel. It is caused by an uninitialized value in the pskb may pull reason and pskb may pull functions, which can lead to a bug in the dccp v6 err function. The vulnerability can be exploited by an attacker to gain unauthorized access to sensitive information. The issue is related to the handling of ICMP messages and the allocation of memory for socket buffers.
Recommendations To resolve the issue, update the Linux kernel to version 6.6.0 or later. If an update is not possible, consider disabling the dccp v4 err and dccp v6 err functions as a temporary workaround. Additionally, restrict access to the vulnerable module to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2023-8487
BDU:2024-01753
CVE-2023-52577
OESA-2024-1482

Affected Products

Alt Linux
Linux Kernel
Red Os