PT-2025-13378 · Linux+3 · Linux Kernel+3
Published
2023-01-11
·
Updated
2026-01-20
·
CVE-2023-53032
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to an integer overflow in the Linux kernel's netfilter ipset bitmap creation routine. Specifically, the
bitmap ip create() function is vulnerable when first ip is 0, last ip is 0xFFFFFFFF, and netmask is 31. The overflow occurs due to a failure to cast operands to a larger data type before performing arithmetic. However, it's noted that this issue is harmless as the value will be checked at the next step. The problem was found by InfoTeCS on behalf of Linux Verification Center.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Insufficiently Random Values
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse