PT-2025-38193 · Linux+4 · Linux Kernel+4
Published
2023-07-08
·
Updated
2025-11-19
·
CVE-2023-53343
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.4.0-11996-gb121d614371c #35
Description
A null pointer dereference issue exists in the Linux kernel's ICMPv6 implementation, specifically within the
icmp6 dev() function. This occurs when processing certain IPv6 Extension Headers (RPL, SRv6, etc.) with link-local addresses as both source and destination. The vulnerability is triggered when a packet is forwarded to an external IP address contained within the IPv6 Extension Header, leading to a dereference of a null pointer in skb rt6 info(skb)->rt6i idev->dev.Recommendations
Update the Linux kernel to version 6.4.0-11996-gb121d614371c #35 or later to resolve this issue.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Suse