CVE-2023-52796
published 2024-05-21CVE-2023-52796: In the Linux kernel, the following vulnerability has been resolved: ipvlan: add ipvlan_route_v6_outbound() helper Inspired by syzbot reports using a stack of…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
ipvlan: add ipvlan_route_v6_outbound() helper
Inspired by syzbot reports using a stack of multiple ipvlan devices.
Reduce stack size needed in ipvlan_process_v6_outbound() by moving
the flowi6 struct used for the route lookup in an non inlined
helper. ipvlan_route_v6_outbound() needs 120 bytes on the stack,
immediately reclaimed.
Also make sure ipvlan_process_v4_outbound() is not inlined.
We might also have to lower MAX_NEST_DEV, because only syzbot uses
setups with more than four stacked devices.
BUG: TASK stack guard page was hit at ffffc9000e803ff8 (stack is ffffc9000e804000..ffffc9000e808000)
stack guard page: 0000 [#1] SMP KASAN
CPU: 0 PID: 13442 Comm: syz-executor.4 Not tainted 6.1.52-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/09/2023
RIP: 0010:kasan_check_range+0x4/0x2a0 mm/kasan/generic.c:188
Code: 48 01 c6 48 89 c7 e8 db 4e c1 03 31 c0 5d c3 cc 0f 0b eb 02 0f 0b b8 ea ff ff ff 5d c3 cc 00 00 cc cc 00 00 cc cc 55 48 89 e5 57 41 56 41 55 41 54 53 b0 01 48 85 f6 0f 84 a4 01 00 00 48 89
RSP: 0018:ffffc9000e804000 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff817e5bf2
RDX: 0000000000000000 RSI: 0000000000000008 RDI: ffffffff887c6568
RBP: ffffc9000e804000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: dffffc0000000001 R12: 1ffff92001d0080c
R13: dffffc0000000000 R14: ffffffff87e6b100 R15: 0000000000000000
FS: 00007fd0c55826c0(0000) GS:ffff8881f6800000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffc9000e803ff8 CR3: 0000000170ef7000 CR4: 00000000003506f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
[] __kasan_check_read+0x11/0x20 mm/kasan/shadow.c:31
[] instrument_atomic_read include/linux/instrumented.h:72 [inline]
[] _test_bit include/asm-generic/bit
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 4f7f850611aa27aaaf1bf5687702ad2240ae442a | 4f7f850611aa27aaaf1bf5687702ad2240ae442a |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 4d2d30f0792b47908af64c4d02ed1ee25ff50542 | 4d2d30f0792b47908af64c4d02ed1ee25ff50542 |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 43b781e7cb5cd0b435de276111953bf2bacd1f02 | 43b781e7cb5cd0b435de276111953bf2bacd1f02 |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 1f64cad3ac38ac5978b53c40e6c5e6fd3477c68f | 1f64cad3ac38ac5978b53c40e6c5e6fd3477c68f |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 732a67ca436887b594ebc43bb5a04ffb0971a760 | 732a67ca436887b594ebc43bb5a04ffb0971a760 |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 8872dc638c24bb774cd2224a69d72a7f661a4d56 | 8872dc638c24bb774cd2224a69d72a7f661a4d56 |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 03cddc4df8c6be47fd27c8f8b87e5f9a989e1458 | 03cddc4df8c6be47fd27c8f8b87e5f9a989e1458 |
| linux | linux | >= 2ad7bf3638411cb547f2823df08166c13ab04269 < 18f039428c7df183b09c69ebf10ffd4e521035d2 | 18f039428c7df183b09c69ebf10ffd4e521035d2 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 3.19 < 4.19.300 | 4.19.300 |
| linux | linux_kernel | >= 4.20 < 5.4.262 | 5.4.262 |
| linux | linux_kernel | >= 5.11 < 5.15.140 | 5.15.140 |
| linux | linux_kernel | >= 5.16 < 6.1.64 | 6.1.64 |
| linux | linux_kernel | >= 5.5 < 5.10.202 | 5.10.202 |
| linux | linux_kernel | >= 6.2 < 6.5.13 | 6.5.13 |
| linux | linux_kernel | >= 6.6 < 6.6.3 | 6.6.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SINEC OS
cisa_ics·2025-08-14
Siemens SINEC OS
ICS Advisory
##
Siemens SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-15
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3.1 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM, SCALANCE
- Vulnerabilities: NULL Pointer Dereference, Use After Free, Unchecked Input for Loop Condition, Out-of-bounds Write, Ou
Red Hat
kernel: ipvlan: add ipvlan_route_v6_outbound() helper
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2023-52796 [HIGH] CWE-121 kernel: ipvlan: add ipvlan_route_v6_outbound() helper
kernel: ipvlan: add ipvlan_route_v6_outbound() helper
In the Linux kernel, the following vulnerability has been resolved:
ipvlan: add ipvlan_route_v6_outbound() helper
Inspired by syzbot reports using a stack of multiple ipvlan devices.
Reduce stack size needed in ipvlan_process_v6_outbound() by moving
the flowi6 struct used for the route lookup in an non inlined
helper. ipvlan_route_v6_outbound() needs 120 bytes on the stack,
immediately reclaimed.
Also make sure ipvlan_process_v4_outbound() is not inlined.
We might also have to lower MAX_NEST_DEV, because only syzbot uses
setups with more than four stacked devices.
BUG: TASK stack guard page was hit at ffffc9000e803ff8 (stack is ffffc9000e804000..ffffc9000e808000)
stack guard page: 0000 [#1] SMP KASAN
CPU: 0 PID: 13442 Comm: syz-executo
Debian
CVE-2023-52796: linux - In the Linux kernel, the following vulnerability has been resolved: ipvlan: add...
vendor_debian·2023·CVSS 7.8
CVE-2023-52796 [HIGH] CVE-2023-52796: linux - In the Linux kernel, the following vulnerability has been resolved: ipvlan: add...
In the Linux kernel, the following vulnerability has been resolved: ipvlan: add ipvlan_route_v6_outbound() helper Inspired by syzbot reports using a stack of multiple ipvlan devices. Reduce stack size needed in ipvlan_process_v6_outbound() by moving the flowi6 struct used for the route lookup in an non inlined helper. ipvlan_route_v6_outbound() needs 120 bytes on the stack, immediately reclaimed. Also make sure ipvlan_process_v4_outbound() is not inlined. We might also have to lower MAX_NEST_DEV, because only syzbot uses setups with more than four stacked devices. BUG: TASK stack guard page was hit at ffffc9000e803ff8 (stack is ffffc9000e804000..ffffc9000e808000) stack guard page: 0000 [#1] SMP KASAN CPU: 0 PID: 13442 Comm: syz-executor.4 Not tainted 6.1.52-syzkaller #0 Hardware name: Goog
GHSA
GHSA-68x5-x32c-8c8w: In the Linux kernel, the following vulnerability has been resolved:
ipvlan: add ipvlan_route_v6_outbound() helper
Inspired by syzbot reports using a
ghsa_unreviewed·2024-05-21
CVE-2023-52796 [HIGH] CWE-787 GHSA-68x5-x32c-8c8w: In the Linux kernel, the following vulnerability has been resolved:
ipvlan: add ipvlan_route_v6_outbound() helper
Inspired by syzbot reports using a
In the Linux kernel, the following vulnerability has been resolved:
ipvlan: add ipvlan_route_v6_outbound() helper
Inspired by syzbot reports using a stack of multiple ipvlan devices.
Reduce stack size needed in ipvlan_process_v6_outbound() by moving
the flowi6 struct used for the route lookup in an non inlined
helper. ipvlan_route_v6_outbound() needs 120 bytes on the stack,
immediately reclaimed.
Also make sure ipvlan_process_v4_outbound() is not inlined.
We might also have to lower MAX_NEST_DEV, because only syzbot uses
setups with more than four stacked devices.
BUG: TASK stack guard page was hit at ffffc9000e803ff8 (stack is ffffc9000e804000..ffffc9000e808000)
stack guard page: 0000 [#1] SMP KASAN
CPU: 0 PID: 13442 Comm: syz-executor.4 Not tainted 6.1.52-syzkaller #0
Hardware name
OSV
CVE-2023-52796: In the Linux kernel, the following vulnerability has been resolved: ipvlan: add ipvlan_route_v6_outbound() helper Inspired by syzbot reports using a s
osv·2024-05-21·CVSS 7.8
CVE-2023-52796 [HIGH] CVE-2023-52796: In the Linux kernel, the following vulnerability has been resolved: ipvlan: add ipvlan_route_v6_outbound() helper Inspired by syzbot reports using a s
In the Linux kernel, the following vulnerability has been resolved: ipvlan: add ipvlan_route_v6_outbound() helper Inspired by syzbot reports using a stack of multiple ipvlan devices. Reduce stack size needed in ipvlan_process_v6_outbound() by moving the flowi6 struct used for the route lookup in an non inlined helper. ipvlan_route_v6_outbound() needs 120 bytes on the stack, immediately reclaimed. Also make sure ipvlan_process_v4_outbound() is not inlined. We might also have to lower MAX_NEST_DEV, because only syzbot uses setups with more than four stacked devices. BUG: TASK stack guard page was hit at ffffc9000e803ff8 (stack is ffffc9000e804000..ffffc9000e808000) stack guard page: 0000 [#1] SMP KASAN CPU: 0 PID: 13442 Comm: syz-executor.4 Not tainted 6.1.52-syzkaller #0 Hardware name: Goog
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/03cddc4df8c6be47fd27c8f8b87e5f9a989e1458https://git.kernel.org/stable/c/18f039428c7df183b09c69ebf10ffd4e521035d2https://git.kernel.org/stable/c/1f64cad3ac38ac5978b53c40e6c5e6fd3477c68fhttps://git.kernel.org/stable/c/43b781e7cb5cd0b435de276111953bf2bacd1f02https://git.kernel.org/stable/c/4d2d30f0792b47908af64c4d02ed1ee25ff50542https://git.kernel.org/stable/c/4f7f850611aa27aaaf1bf5687702ad2240ae442ahttps://git.kernel.org/stable/c/732a67ca436887b594ebc43bb5a04ffb0971a760https://git.kernel.org/stable/c/8872dc638c24bb774cd2224a69d72a7f661a4d56https://git.kernel.org/stable/c/03cddc4df8c6be47fd27c8f8b87e5f9a989e1458https://git.kernel.org/stable/c/18f039428c7df183b09c69ebf10ffd4e521035d2https://git.kernel.org/stable/c/1f64cad3ac38ac5978b53c40e6c5e6fd3477c68fhttps://git.kernel.org/stable/c/43b781e7cb5cd0b435de276111953bf2bacd1f02https://git.kernel.org/stable/c/4d2d30f0792b47908af64c4d02ed1ee25ff50542https://git.kernel.org/stable/c/4f7f850611aa27aaaf1bf5687702ad2240ae442ahttps://git.kernel.org/stable/c/732a67ca436887b594ebc43bb5a04ffb0971a760https://git.kernel.org/stable/c/8872dc638c24bb774cd2224a69d72a7f661a4d56
2024-05-21
Published