CVE-2023-1691
published 2023-07-06CVE-2023-1691: Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.39%
31.1th percentile
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | emui | — | — |
| huawei | emui | — | — |
| huawei | emui | — | — |
| huawei | emui | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-64f4-qr63-vg45: Vulnerability of failures to capture exceptions in the communication framework
ghsa_unreviewed·2023-07-06
CVE-2023-1691 [HIGH] CWE-248 GHSA-64f4-qr63-vg45: Vulnerability of failures to capture exceptions in the communication framework
Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.
Red Hat
kernel: tunnels: fix kasan splat when generating ipv4 pmtu error
vendor_redhat·2025-10-04·CVSS 7.1
CVE-2023-53600 [HIGH] CWE-125 kernel: tunnels: fix kasan splat when generating ipv4 pmtu error
kernel: tunnels: fix kasan splat when generating ipv4 pmtu error
In the Linux kernel, the following vulnerability has been resolved:
tunnels: fix kasan splat when generating ipv4 pmtu error
If we try to emit an icmp error in response to a nonliner skb, we get
BUG: KASAN: slab-out-of-bounds in ip_compute_csum+0x134/0x220
Read of size 4 at addr ffff88811c50db00 by task iperf3/1691
CPU: 2 PID: 1691 Comm: iperf3 Not tainted 6.5.0-rc3+ #309
[..]
kasan_report+0x105/0x140
ip_compute_csum+0x134/0x220
iptunnel_pmtud_build_icmp+0x554/0x1020
skb_tunnel_check_pmtu+0x513/0xb80
vxlan_xmit_one+0x139e/0x2ef0
vxlan_xmit+0x1867/0x2760
dev_hard_start_xmit+0x1ee/0x4f0
br_dev_queue_push_xmit+0x4d1/0x660
[..]
ip_compute_csum() cannot deal with nonlinear skbs, so avoid it.
After this change, splat is gone and i
No detection rules found.
No public exploits indexed.
https://consumer.huawei.com/en/support/bulletin/2023/7/https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858https://consumer.huawei.com/en/support/bulletin/2023/7/https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858
2023-07-06
Published