CVE-2023-53705

HIGHCVSS 8.2/10EPSS 0.21%

Last modified

CVE-2023-53705 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

Metrics

CVSS 3.1
8.2/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

EPSS Probability
0.21%

11.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= c61a404325093250b676f40ad8f4dd00f3bcab5f, < 59e656d0d4a84ea0ee9a39c6f69160a3effccc94; >= c61a404325093250b676f40ad8f4dd00f3bcab5f, < 04bf69e3de435d793a203aacc4b774f8f9f2baeb; >= c61a404325093250b676f40ad8f4dd00f3bcab5f, < 011f47c8b8389154f996f5f69da8efc3a3beefef; >= c61a404325093250b676f40ad8f4dd00f3bcab5f, < e5f82688ae10f5f386952e65e941bb8868ee54dc; >= c61a404325093250b676f40ad8f4dd00f3bcab5f, < 9b92e2d0eb696d7586ba832c8854653b59887da0; >= c61a404325093250b676f40ad8f4dd00f3bcab5f, < 91dd8aab9c9f193210681b86b6b92840ffe74f0c; >= c61a404325093250b676f40ad8f4dd00f3bcab5f, < ae68c0f7edbc9a294094ce03a0aaf45aa489ce40; >= c61a404325093250b676f40ad8f4dd00f3bcab5f, < 878ecb0897f4737a4c9401f3523fd49589025671
LinuxLinux2.6.19

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2023-53705?
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
How severe is CVE-2023-53705?
CVE-2023-53705 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2023-53705?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2023

Are you affected by CVE-2023-53705?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST