PT-2025-40764 · Linux+1 · Linux Kernel+1

Published

2023-06-23

·

Updated

2025-12-04

·

CVE-2023-53601

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.30-syzkaller
Description The Linux kernel had a flaw where drivers incorrectly assumed that skb mac header was always set during network packet transmission. Specifically, the ndo start xmit() function was used without verifying the presence of the mac header, leading to potential issues. This was identified through syzbot testing, resulting in warnings related to skb mac header and bond xmit hash within the bonding driver. The issue could occur during the transmission of network packets, potentially causing unexpected behavior or system instability. The bond xmit hash, bond xmit 3ad xor slave get, bond 3ad xor xmit, bond start xmit, and bond start xmit functions were implicated in the issue.
Recommendations Update the Linux kernel to version 6.1.30-syzkaller or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04425
CVE-2023-53601
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4301-1
SUSE-SU-2025:4320-1

Affected Products

Linux Kernel
Suse