PT-2025-13346 · Linux+3 · Linux Kernel+3
Published
2025-01-19
·
Updated
2025-10-30
·
CVE-2023-53000
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A potential issue has been resolved in the Linux kernel related to netlink attributes. The
nla type(nla) function is used to parse and validate netlink attributes, and the type variable is then used as an array index. This could potentially be used as a Spectre v1 gadget, allowing malicious users to leak kernel memory content. The array index nospec() function can be used to prevent this. An audit is needed to ensure all netlink uses are properly validated.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Validation of Array Index
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse