CVE-2023-3773Out-of-bounds Read in Linux

Severity
7.8HIGHNVD
NVD4.4CNA5.5OSV4.7OSV4.6OSV4.4
EPSS
0.0%
top 95.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 25
Latest updateDec 24

Description

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 0.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5linux/linux13b00b135665c92065a27c0c39dd97e0f380bd4f8ad9bc25cbdcec72e7ca43dd8281decb69ea9a70+15
Linuxlinux/linux_kernel5.19.06.1.47+1
NVDlinux/linux_kernel6.46.4.8+4
Debianlinux/linux_kernel< 5.10.197-1+5
Ubuntulinux/linux_kernel< 5.15.0-91.101

Also affects: Debian Linux 10.0, 12.0, Enterprise Linux 8.0, 9.0

🔴Vulnerability Details

29
GHSA
GHSA-8vph-jw2x-79f2: In the Linux kernel, the following vulnerability has been resolved: vdpa: Add queue index attr to vdpa_nl_policy for nlattr length check The vdpa_nl2025-12-24
CVEList
vdpa: Add queue index attr to vdpa_nl_policy for nlattr length check2025-12-24
OSV
CVE-2023-54031: In the Linux kernel, the following vulnerability has been resolved: vdpa: Add queue index attr to vdpa_nl_policy for nlattr length check The vdpa_nl_p2025-12-24
OSV
vdpa: Add queue index attr to vdpa_nl_policy for nlattr length check2025-12-24
OSV
CVE-2023-53652: In the Linux kernel, the following vulnerability has been resolved: vdpa: Add features attr to vdpa_nl_policy for nlattr length check The vdpa_nl_poli2025-10-07

📋Vendor Advisories

19
Red Hat
kernel: vdpa: Add queue index attr to vdpa_nl_policy for nlattr length check2025-12-24
Red Hat
kernel: vdpa: Add features attr to vdpa_nl_policy for nlattr length check2025-10-07
Red Hat
kernel: vdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check2025-10-04
Red Hat
kernel: macvlan: add forgotten nla_policy for IFLA_MACVLAN_BC_CUTOFF2025-10-01
Ubuntu
Linux kernel vulnerabilities2024-01-10

🕵️Threat Intelligence

1
Wiz
CVE-2023-54031 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2023-3773 kernel: xfrm: out-of-bounds read of XFRMA_MTIMER_THRESH nlattr2023-06-30