PT-2023-8806 · Linux+6 · Linux Kernel+6

Published

2023-12-13

·

Updated

2025-09-29

·

CVE-2023-52435

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.7.0
Description The vulnerability is related to the skb segment function in the Linux kernel's networking component. It can cause a general protection fault due to a null pointer dereference when the mss value exceeds the maximum allowed value. The issue arises from the computation mss = mss * partial segs, which can lead to a bad final result if the initial mss value is not properly limited. The vulnerability can be exploited to crash the kernel.
Recommendations To resolve the issue, update the Linux kernel to version 6.7.0 or later, which includes the fix for the skb segment function. Alternatively, apply the patch that limits the segmentation to prevent the mss value from exceeding the maximum allowed value.
Note: The provided input data does not specify the exact version that contains the fix, but it is mentioned that the issue is resolved in the Linux kernel. Therefore, updating to the latest version available is recommended.

Exploit

Fix

NULL Pointer Dereference

Buffer Overflow

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-14046
ALT-PU-2024-3291
ALT-PU-2024-3457
ALT-PU-2024-4623
ALT-PU-2024-6511
ALT-PU-2024-6818
AZL-35811
BDU:2024-01977
CVE-2023-52435
DLA-3842-1
DSA-5658-1
DSA-5681-1
OESA-2024-1239
OESA-2024-1240
OESA-2024-1241
OESA-2024-1242
OESA-2024-1243
OESA-2024-1244
OPENSUSE-SU-2024_2947-1
SUSE-SU-2024:2802-1
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6724-1
USN-6724-2
USN-6766-1
USN-6766-2
USN-6766-3
USN-6767-1
USN-6767-2
USN-6795-1
USN-6828-1
USN-6926-1
USN-6926-2
USN-6926-3

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu