PT-2025-13346 · Linux+3 · Linux Kernel+3

Published

2025-01-19

·

Updated

2025-10-30

·

CVE-2023-53000

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential issue has been resolved in the Linux kernel related to netlink attributes. The nla type(nla) function is used to parse and validate netlink attributes, and the type variable is then used as an array index. This could potentially be used as a Spectre v1 gadget, allowing malicious users to leak kernel memory content. The array index nospec() function can be used to prevent this. An audit is needed to ensure all netlink uses are properly validated.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Validation of Array Index

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06362
CVE-2023-53000
OPENSUSE-SU-2025_1195-1
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:02099-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1195-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025:1293-1
SUSE-SU-2025_02099-1
SUSE-SU-2025_1195-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
SUSE-SU-2025_1293-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse