PT-2025-13379 · Linux+4 · Linux Kernel+4

Published

2023-01-11

·

Updated

2025-09-29

·

CVE-2023-53033

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to incorrect arithmetic operations when fetching VLAN header bits in the netfilter component of the Linux kernel. Specifically, when the offset and length exceed the boundaries of the ethernet and VLAN header, the length is adjusted to copy bytes within the scratchpad area, and remaining bytes are copied directly from the skbuff data area. The problem arises from using an incorrect arithmetic operator, which is fixed by subtracting the size of the VLAN header in the case of double-tagged packets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-06025
CVE-2023-53033
OPENSUSE-SU-2025_01633-1
OPENSUSE-SU-2025_1195-1
RHSA-2023:2458
RHSA-2023_2458
SUSE-SU-2025:01633-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1195-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1574-1
SUSE-SU-2025_01633-1
SUSE-SU-2025_1195-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Red Os
Suse