cbcvebase.
CVE-2023-53141
published 2025-05-02

CVE-2023-53141: In the Linux kernel, the following vulnerability has been resolved: ila: do not generate empty messages in ila_xlat_nl_cmd_get_mapping()…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ila: do not generate empty messages in ila_xlat_nl_cmd_get_mapping() ila_xlat_nl_cmd_get_mapping() generates an empty skb, triggerring a recent sanity check [1]. Instead, return an error code, so that user space can get it. [1] skb_assert_len WARNING: CPU: 0 PID: 5923 at include/linux/skbuff.h:2527 skb_assert_len include/linux/skbuff.h:2527 [inline] WARNING: CPU: 0 PID: 5923 at include/linux/skbuff.h:2527 __dev_queue_xmit+0x1bc0/0x3488 net/core/dev.c:4156 Modules linked in: CPU: 0 PID: 5923 Comm: syz-executor269 Not tainted 6.2.0-syzkaller-18300-g2ebd1fbb946d #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/21/2023 pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : skb_assert_len include/linux/skbuff.h:2527 [inline] pc : __dev_queue_xmit+0x1bc0/0x3488 net/core/dev.c:4156 lr : skb_assert_len include/linux/skbuff.h:2527 [inline] lr : __dev_queue_xmit+0x1bc0/0x3488 net/core/dev.c:4156 sp : ffff80001e0d6c40 x29: ffff80001e0d6e60 x28: dfff800000000000 x27: ffff0000c86328c0 x26: dfff800000000000 x25: ffff0000c8632990 x24: ffff0000c8632a00 x23: 0000000000000000 x22: 1fffe000190c6542 x21: ffff0000c8632a10 x20: ffff0000c8632a00 x19: ffff80001856e000 x18: ffff80001e0d5fc0 x17: 0000000000000000 x16: ffff80001235d16c x15: 0000000000000000 x14: 0000000000000000 x13: 0000000000000001 x12: 0000000000000001 x11: ff80800008353a30 x10: 0000000000000000 x9 : 21567eaf25bfb600 x8 : 21567eaf25bfb600 x7 : 0000000000000001 x6 : 0000000000000001 x5 : ffff80001e0d6558 x4 : ffff800015c74760 x3 : ffff800008596744 x2 : 0000000000000001 x1 : 0000000100000000 x0 : 000000000000000e Call trace: skb_assert_len include/linux/skbuff.h:2527 [inline] __dev_queue_xmit+0x1bc0/0x3488 net/core/dev.c:4156 dev_queue_xmit include/linux/netdevice.h:3033 [inline] __netlink_deliver_tap_skb net/netlink/af_netlink.c:307 [inline] __netlink_deliver_tap+0x45c/0x6f8 net/netlink/af_netlink.c:325

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < b26bc5861505f04dea933ca3e522772b20fa086fb26bc5861505f04dea933ca3e522772b20fa086f
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < c631e52aea0fc8d4deea06e439f5810a8b40ad0fc631e52aea0fc8d4deea06e439f5810a8b40ad0f
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 783f218940b3c7b872e4111d0145000f26ecbdf6783f218940b3c7b872e4111d0145000f26ecbdf6
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 42d9ed4e5dc5f87fbd67c232e2e4a9b88ceeb47f42d9ed4e5dc5f87fbd67c232e2e4a9b88ceeb47f
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 91aceb3844d4aec555c7f423f9fd843eff5835e991aceb3844d4aec555c7f423f9fd843eff5835e9
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 25b54f247ea060aeb85ec88a82c75060fca0352125b54f247ea060aeb85ec88a82c75060fca03521
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 60fe7cb483c8c5dcadaeeac867251d6e59c7badc60fe7cb483c8c5dcadaeeac867251d6e59c7badc
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 693aa2c0d9b6d5b1f2745d31b6e70d09dbbaf06e693aa2c0d9b6d5b1f2745d31b6e70d09dbbaf06e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 5.4.0-205.2255.4.0-205.225
linuxlinux_kernel>= 4.15 < 4.19.2784.19.278
linuxlinux_kernel>= 4.20 < 5.4.2375.4.237
linuxlinux_kernel>= 4.5 < 4.14.3104.14.310
linuxlinux_kernel>= 5.11 < 5.15.1035.15.103
linuxlinux_kernel>= 5.16 < 6.1.206.1.20
linuxlinux_kernel>= 5.5 < 5.10.1755.10.175
linuxlinux_kernel>= 6.2 < 6.2.76.2.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.7MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.