cbcvebase.
CVE-2023-53684
published 2025-10-07

CVE-2023-53684: In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero padding when dumping algos and encap When copying data to user-space we should…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.5th percentile
In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero padding when dumping algos and encap When copying data to user-space we should ensure that only valid data is copied over. Padding in structures may be filled with random (possibly sensitve) data and should never be given directly to user-space. This patch fixes the copying of xfrm algorithms and the encap template in xfrm_user so that padding is zeroed.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 0725daaa9a879388ed312110f62dbd5ea2d75f8f0725daaa9a879388ed312110f62dbd5ea2d75f8f
linuxlinux>= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 5218af4ad5d8948faac19f71583bcd786c3852df5218af4ad5d8948faac19f71583bcd786c3852df
linuxlinux>= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 1a351e26cc010d6991fbbd5701ac16581372e26f1a351e26cc010d6991fbbd5701ac16581372e26f
linuxlinux>= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 8222d5910dae08213b6d9d4bc9a7f8502855e6248222d5910dae08213b6d9d4bc9a7f8502855e624
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.11 < 5.15.1065.15.106
linuxlinux_kernel>= 5.16 < 6.1.236.1.23
linuxlinux_kernel>= 6.2 < 6.2.106.2.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.