PT-2025-38351 · Linux+1 · Linux Kernel+1

Published

2023-04-13

·

Updated

2025-10-31

·

CVE-2023-53372

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue in the sctp ifwdtsn skip function. A potential overflow can occur when traversing ifwdtsn skips, specifically during the dereference of data within the sctp ifwdtsn skip structure. This happens because the code only checks the position against the end of the chunk, failing to account for the size of the structure itself.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-03797
CVE-2023-53372
OESA-2025-2553
RHSA-2023:6583
RHSA-2023:7077
RHSA-2024:0575

Affected Products

Astra Linux
Linux Kernel