PT-2025-38215 · Linux+4 · Linux Kernel+4
Published
2023-08-02
·
Updated
2025-12-04
·
CVE-2023-53365
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.5.0-rc3-00044-g0a8db05b571a
Description
A flaw exists in the Linux kernel related to IPv6 Multicast Routing (ip6mr). Specifically, a potential
skb under panic issue occurs within the ip6mr cache report() function when a VLAN device is configured on a pim6reg device. This can lead to an invalid memory address being used during an skb push operation, resulting in a kernel BUG. The issue arises when a DAD (Duplicate Address Detection) Neighbor Solicitation packet is sent through reg vif xmit(), triggering the vulnerability in ip6mr cache report(). The skb push() function attempts to adjust the skb->data pointer by a negative offset, leading to an out-of-bounds memory access.Recommendations
Update to Linux kernel version 6.5.0-rc3-00044-g0a8db05b571a or a later version to resolve this issue.
Exploit
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Suse