PT-2025-13379 · Linux+4 · Linux Kernel+4
Published
2023-01-11
·
Updated
2025-09-29
·
CVE-2023-53033
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to incorrect arithmetic operations when fetching VLAN header bits in the netfilter component of the Linux kernel. Specifically, when the offset and length exceed the boundaries of the ethernet and VLAN header, the length is adjusted to copy bytes within the scratchpad area, and remaining bytes are copied directly from the skbuff data area. The problem arises from using an incorrect arithmetic operator, which is fixed by subtracting the size of the VLAN header in the case of double-tagged packets.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat
Red Os
Suse