CVE-2023-53535
published 2025-10-04CVE-2023-53535: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Add a check for oversized packets Occasionnaly we may get oversized packets…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: Add a check for oversized packets
Occasionnaly we may get oversized packets from the hardware which
exceed the nomimal 2KiB buffer size we allocate SKBs with. Add an early
check which drops the packet to avoid invoking skb_over_panic() and move
on to processing the next packet.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < 7cdb07e10c1258c08f31b24898930e4ece88d163 | 7cdb07e10c1258c08f31b24898930e4ece88d163 |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < c34b1c0870323649d45c5074828d7f754dea2673 | c34b1c0870323649d45c5074828d7f754dea2673 |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < 87363d1ab55e497702a9506ff423c422639c8a25 | 87363d1ab55e497702a9506ff423c422639c8a25 |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < 841881320562cbeac7046b537b91cd000480cea2 | 841881320562cbeac7046b537b91cd000480cea2 |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < 124ca24e0de958d2e20e0aa1e2434af7b72f8887 | 124ca24e0de958d2e20e0aa1e2434af7b72f8887 |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < 5f56767fb5f2df875b6553e08dbec6a45431c988 | 5f56767fb5f2df875b6553e08dbec6a45431c988 |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < 411317d2a4a7d6049d8efeef0d32ae43f8baefce | 411317d2a4a7d6049d8efeef0d32ae43f8baefce |
| linux | linux | >= 1c1008c793fa46703a2fee469f4235e1c7984333 < 5c0862c2c962052ed5055220a00ac1cefb92fbcd | 5c0862c2c962052ed5055220a00ac1cefb92fbcd |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 3.15 < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 4.15 < 4.19.276 | 4.19.276 |
| linux | linux_kernel | >= 4.20 < 5.4.235 | 5.4.235 |
| linux | linux_kernel | >= 5.11 < 5.15.99 | 5.15.99 |
| linux | linux_kernel | >= 5.16 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 5.5 < 5.10.173 | 5.10.173 |
| linux | linux_kernel | >= 6.2 < 6.2.3 | 6.2.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wh7j-wv38-gcf6: In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: Add a check for oversized packets
Occasionnaly we may get oversiz
ghsa_unreviewed·2025-10-04
CVE-2023-53535 [MEDIUM] GHSA-wh7j-wv38-gcf6: In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: Add a check for oversized packets
Occasionnaly we may get oversiz
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: Add a check for oversized packets
Occasionnaly we may get oversized packets from the hardware which
exceed the nomimal 2KiB buffer size we allocate SKBs with. Add an early
check which drops the packet to avoid invoking skb_over_panic() and move
on to processing the next packet.
OSV
CVE-2023-53535: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Add a check for oversized packets Occasionnaly we may get oversized
osv·2025-10-04·CVSS 5.5
CVE-2023-53535 [MEDIUM] CVE-2023-53535: In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Add a check for oversized packets Occasionnaly we may get oversized
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Add a check for oversized packets Occasionnaly we may get oversized packets from the hardware which exceed the nomimal 2KiB buffer size we allocate SKBs with. Add an early check which drops the packet to avoid invoking skb_over_panic() and move on to processing the next packet.
Red Hat
kernel: net: bcmgenet: Add a check for oversized packets
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2023-53535 [MEDIUM] CWE-787 kernel: net: bcmgenet: Add a check for oversized packets
kernel: net: bcmgenet: Add a check for oversized packets
In the Linux kernel, the following vulnerability has been resolved:
net: bcmgenet: Add a check for oversized packets
Occasionnaly we may get oversized packets from the hardware which
exceed the nomimal 2KiB buffer size we allocate SKBs with. Add an early
check which drops the packet to avoid invoking skb_over_panic() and move
on to processing the next packet.
A missing bounds check flaw was found in the Linux kernel's Broadcom GENET Ethernet driver in the packet receive path.
A local user on systems with this hardware can trigger this issue when the network interface receives oversized packets from the network that exceed the nominal 2KiB buffer allocation. This causes the driver to invoke skb_over_panic, resulting in a kernel pani
Debian
CVE-2023-53535: linux - In the Linux kernel, the following vulnerability has been resolved: net: bcmgen...
vendor_debian·2023·CVSS 5.5
CVE-2023-53535 [MEDIUM] CVE-2023-53535: linux - In the Linux kernel, the following vulnerability has been resolved: net: bcmgen...
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Add a check for oversized packets Occasionnaly we may get oversized packets from the hardware which exceed the nomimal 2KiB buffer size we allocate SKBs with. Add an early check which drops the packet to avoid invoking skb_over_panic() and move on to processing the next packet.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/124ca24e0de958d2e20e0aa1e2434af7b72f8887https://git.kernel.org/stable/c/411317d2a4a7d6049d8efeef0d32ae43f8baefcehttps://git.kernel.org/stable/c/5c0862c2c962052ed5055220a00ac1cefb92fbcdhttps://git.kernel.org/stable/c/5f56767fb5f2df875b6553e08dbec6a45431c988https://git.kernel.org/stable/c/7cdb07e10c1258c08f31b24898930e4ece88d163https://git.kernel.org/stable/c/841881320562cbeac7046b537b91cd000480cea2https://git.kernel.org/stable/c/87363d1ab55e497702a9506ff423c422639c8a25https://git.kernel.org/stable/c/c34b1c0870323649d45c5074828d7f754dea2673
2025-10-04
Published