cbcvebase.
CVE-2023-53000
published 2025-03-27

CVE-2023-53000: In the Linux kernel, the following vulnerability has been resolved: netlink: prevent potential spectre v1 gadgets Most netlink attributes are parsed and…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved: netlink: prevent potential spectre v1 gadgets Most netlink attributes are parsed and validated from __nla_validate_parse() or validate_nla() u16 type = nla_type(nla); if (type == 0 || type > maxtype) { /* error or continue */ } @type is then used as an array index and can be used as a Spectre v1 gadget. array_index_nospec() can be used to prevent leaking content of kernel memory to malicious users. This should take care of vast majority of netlink uses, but an audit is needed to take care of others where validation is not yet centralized in core netlink functions.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= bfa83a9e03cf8d501c6272999843470afecb32ed < 3e5082b1c66c7783fbcd79b5b178573230e528ff3e5082b1c66c7783fbcd79b5b178573230e528ff
linuxlinux>= bfa83a9e03cf8d501c6272999843470afecb32ed < 539ca5dcbc91134bbe2c45677811c31d8b030d2d539ca5dcbc91134bbe2c45677811c31d8b030d2d
linuxlinux>= bfa83a9e03cf8d501c6272999843470afecb32ed < 41b74e95f297ac360ca7ed6bf200100717cb6c4541b74e95f297ac360ca7ed6bf200100717cb6c45
linuxlinux>= bfa83a9e03cf8d501c6272999843470afecb32ed < 992e4ff7116a77968039277b5d6aaa535c2f2184992e4ff7116a77968039277b5d6aaa535c2f2184
linuxlinux>= bfa83a9e03cf8d501c6272999843470afecb32ed < f0950402e8c76e7dcb08563f1b4e8000fbc62455f0950402e8c76e7dcb08563f1b4e8000fbc62455
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 2.6.15 < 5.4.2315.4.231
linuxlinux_kernel>= 5.11 < 5.15.915.15.91
linuxlinux_kernel>= 5.16 < 6.1.96.1.9
linuxlinux_kernel>= 5.5 < 5.10.1665.10.166

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.