PT-2024-14652 · Linux+10 · Linux Kernel+10

Tao Liu

·

Published

2023-12-28

·

Updated

2026-03-14

·

CVE-2023-52610

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.7.0-rc3
Description The Linux kernel has a vulnerability in the net/sched module, specifically in the act ct function. This function adds a reference to the skb (socket buffer) before defragmentation, which can lead to a crash when the skb is cloned and shared at the same time. The issue arises when fragments arrive out of order, causing the last fragment's reference to be reset, resulting in a memory leak. The situation worsens when packet capture is initiated, leading to a crash. The vulnerability is fixed by removing the skb get() call before defragmentation.
Recommendations For Linux kernel versions prior to 6.7.0-rc3, update to a newer version that includes the fix for this vulnerability. If updating is not possible, consider disabling the act ct function or restricting its use to minimize the risk of exploitation. Additionally, avoid using the skb clone() function in conjunction with act ct to prevent the crash.

Exploit

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2394
ALSA-2024:3618
ALSA-2024:3627
ALSA-2024_2394
ALSA-2025_16880
BDU:2025-14281
CESA-2024_3618
CESA-2024_3627
CVE-2023-52610
INFSA-2024_2394
INFSA-2024_3618
INFSA-2024_3627
OESA-2024-1566
OPENSUSE-SU-2024_3551-1
OPENSUSE-SU-2024_3561-1
OPENSUSE-SU-2024_3564-1
OPENSUSE-SU-2024_3587-1
OPENSUSE-SU-2024_3592-1
RHSA-2024:2394
RHSA-2024:3618
RHSA-2024:3627
RHSA-2024:5255
RHSA-2024:5692
RHSA-2024_2394
RHSA-2024_3618
RHSA-2024_3627
RHSA-2025:22997
RHSA-2025:22999
RLSA-2024:3618
RLSA-2024:3627
SUSE-SU-2024:3551-1
SUSE-SU-2024:3561-1
SUSE-SU-2024:3564-1
SUSE-SU-2024:3569-1
SUSE-SU-2024:3587-1
SUSE-SU-2024:3592-1
SUSE-SU-2025:20073-1
SUSE-SU-2025:20077-1
USN-6725-1
USN-6725-2
USN-6765-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu