CVE-2023-53684
published 2025-10-07CVE-2023-53684: In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero padding when dumping algos and encap When copying data to user-space we should…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Zero padding when dumping algos and encap
When copying data to user-space we should ensure that only valid
data is copied over. Padding in structures may be filled with
random (possibly sensitve) data and should never be given directly
to user-space.
This patch fixes the copying of xfrm algorithms and the encap
template in xfrm_user so that padding is zeroed.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.25-1 (bookworm) | linux 6.1.25-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 0725daaa9a879388ed312110f62dbd5ea2d75f8f | 0725daaa9a879388ed312110f62dbd5ea2d75f8f |
| linux | linux | >= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 5218af4ad5d8948faac19f71583bcd786c3852df | 5218af4ad5d8948faac19f71583bcd786c3852df |
| linux | linux | >= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 1a351e26cc010d6991fbbd5701ac16581372e26f | 1a351e26cc010d6991fbbd5701ac16581372e26f |
| linux | linux | >= c7a5899eb26e2a4d516d53f65b6dd67be2228041 < 8222d5910dae08213b6d9d4bc9a7f8502855e624 | 8222d5910dae08213b6d9d4bc9a7f8502855e624 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 0 < 6.1.25-1 | 6.1.25-1 |
| linux | linux_kernel | >= 5.11 < 5.15.106 | 5.15.106 |
| linux | linux_kernel | >= 5.16 < 6.1.23 | 6.1.23 |
| linux | linux_kernel | >= 6.2 < 6.2.10 | 6.2.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53684: In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero padding when dumping algos and encap When copying data to user-space we
osv·2025-10-07·CVSS 5.5
CVE-2023-53684 [MEDIUM] CVE-2023-53684: In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero padding when dumping algos and encap When copying data to user-space we
In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero padding when dumping algos and encap When copying data to user-space we should ensure that only valid data is copied over. Padding in structures may be filled with random (possibly sensitve) data and should never be given directly to user-space. This patch fixes the copying of xfrm algorithms and the encap template in xfrm_user so that padding is zeroed.
GHSA
GHSA-pmq6-ggff-fwmg: In the Linux kernel, the following vulnerability has been resolved:
xfrm: Zero padding when dumping algos and encap
When copying data to user-space
ghsa_unreviewed·2025-10-07
CVE-2023-53684 [MEDIUM] GHSA-pmq6-ggff-fwmg: In the Linux kernel, the following vulnerability has been resolved:
xfrm: Zero padding when dumping algos and encap
When copying data to user-space
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Zero padding when dumping algos and encap
When copying data to user-space we should ensure that only valid
data is copied over. Padding in structures may be filled with
random (possibly sensitve) data and should never be given directly
to user-space.
This patch fixes the copying of xfrm algorithms and the encap
template in xfrm_user so that padding is zeroed.
Red Hat
kernel: xfrm: Zero padding when dumping algos and encap
vendor_redhat·2025-10-07·CVSS 5.5
CVE-2023-53684 [MEDIUM] CWE-200 kernel: xfrm: Zero padding when dumping algos and encap
kernel: xfrm: Zero padding when dumping algos and encap
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Zero padding when dumping algos and encap
When copying data to user-space we should ensure that only valid
data is copied over. Padding in structures may be filled with
random (possibly sensitve) data and should never be given directly
to user-space.
This patch fixes the copying of xfrm algorithms and the encap
template in xfrm_user so that padding is zeroed.
Statement: Zeroing of structure padding was missing when dumping XFRM algorithms/encap via netlink, allowing leakage of uninitialized kernel bytes to user space. Impact is confidentiality-only and typically requires CAP_NET_ADMIN, so PR is High (PR:H).
Package: kernel (Red Hat Enterprise Linux 10) - Not
Debian
CVE-2023-53684: linux - In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero ...
vendor_debian·2023·CVSS 5.5
CVE-2023-53684 [MEDIUM] CVE-2023-53684: linux - In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero ...
In the Linux kernel, the following vulnerability has been resolved: xfrm: Zero padding when dumping algos and encap When copying data to user-space we should ensure that only valid data is copied over. Padding in structures may be filled with random (possibly sensitve) data and should never be given directly to user-space. This patch fixes the copying of xfrm algorithms and the encap template in xfrm_user so that padding is zeroed.
Scope: local
bookworm: resolved (fixed in 6.1.25-1)
bullseye: resolved
forky: resolved (fixed in 6.1.25-1)
sid: resolved (fixed in 6.1.25-1)
trixie: resolved (fixed in 6.1.25-1)
No detection rules found.
No public exploits indexed.
2025-10-07
Published