CVE-2023-53716
published 2025-10-22CVE-2023-53716: In the Linux kernel, the following vulnerability has been resolved: net: fix skb leak in __skb_tstamp_tx() Commit 50749f2dd685 ("tcp/udp: Fix memleaks of sk…
PriorityP420low5.5
EPSS
0.20%
9.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: fix skb leak in __skb_tstamp_tx()
Commit 50749f2dd685 ("tcp/udp: Fix memleaks of sk and zerocopy skbs with
TX timestamp.") added a call to skb_orphan_frags_rx() to fix leaks with
zerocopy skbs. But it ended up adding a leak of its own. When
skb_orphan_frags_rx() fails, the function just returns, leaking the skb
it just cloned. Free it before returning.
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1f69c086b20e27763af28145981435423f088268 < 779332447108545ef04682ea29af5f85c0202aee | 779332447108545ef04682ea29af5f85c0202aee |
| linux | linux | >= 230a5ed7d813fb516de81d23f09d7506753e41e9 < a594382ec6d0cc8cff5a8bc7e61b54e3858fb243 | a594382ec6d0cc8cff5a8bc7e61b54e3858fb243 |
| linux | linux | >= 281072fb2a7294cde7acbf5375b879f40a8001b7 < 82501f1ead557cbee1c2467654ec109a80334d22 | 82501f1ead557cbee1c2467654ec109a80334d22 |
| linux | linux | >= 4.14.315 < 4.14.316 | 4.14.316 |
| linux | linux | >= 4.19.283 < 4.19.284 | 4.19.284 |
| linux | linux | >= 426384dd4980040651536fef5feac4dcc4d7ee4e < f4d928c00254cfc9dd0ee7076f4a59bceec675f4 | f4d928c00254cfc9dd0ee7076f4a59bceec675f4 |
| linux | linux | >= 43e4197dd5f6b474a8b16f8b6a42cd45cf4f9d1a < e06841a2abf9c82735cee39e88b1d79464088840 | e06841a2abf9c82735cee39e88b1d79464088840 |
| linux | linux | >= 5.10.180 < 5.10.181 | 5.10.181 |
| linux | linux | >= 5.15.111 < 5.15.114 | 5.15.114 |
| linux | linux | >= 5.4.243 < 5.4.244 | 5.4.244 |
| linux | linux | >= 50749f2dd6854a41830996ad302aef2ffaf011d8 < 8a02fb71d7192ff1a9a47c9d937624966c6e09af | 8a02fb71d7192ff1a9a47c9d937624966c6e09af |
| linux | linux | >= 6.1.28 < 6.1.31 | 6.1.31 |
| linux | linux | >= 6.2.15 < 6.3 | 6.3 |
| linux | linux | >= 6.3.2 < 6.3.5 | 6.3.5 |
| linux | linux | >= 602fa8af44fd55a58f9e94eb673e8adad2c6cc46 < 58766252f6b2c0487cda6976a53d2bb03ae28e2a | 58766252f6b2c0487cda6976a53d2bb03ae28e2a |
| linux | linux | >= cb52e7f24c1d01a536a847dff0d1d95889cc3b5c < cc18b4685910d5d9de8314bae9c55790701b1811 | cc18b4685910d5d9de8314bae9c55790701b1811 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.14.315 < 4.14.316 | 4.14.316 |
| linux | linux_kernel | >= 4.19.283 < 4.19.284 | 4.19.284 |
| linux | linux_kernel | >= 5.10.180 < 5.10.181 | 5.10.181 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
net: fix skb leak in __skb_tstamp_tx()
osv·2025-10-22
CVE-2023-53716 net: fix skb leak in __skb_tstamp_tx()
net: fix skb leak in __skb_tstamp_tx()
In the Linux kernel, the following vulnerability has been resolved:
net: fix skb leak in __skb_tstamp_tx()
Commit 50749f2dd685 ("tcp/udp: Fix memleaks of sk and zerocopy skbs with
TX timestamp.") added a call to skb_orphan_frags_rx() to fix leaks with
zerocopy skbs. But it ended up adding a leak of its own. When
skb_orphan_frags_rx() fails, the function just returns, leaking the skb
it just cloned. Free it before returning.
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.
GHSA
GHSA-rxxr-3f5p-3hc6: In the Linux kernel, the following vulnerability has been resolved:
net: fix skb leak in __skb_tstamp_tx()
Commit 50749f2dd685 ("tcp/udp: Fix memlea
ghsa_unreviewed·2025-10-22
CVE-2023-53716 GHSA-rxxr-3f5p-3hc6: In the Linux kernel, the following vulnerability has been resolved:
net: fix skb leak in __skb_tstamp_tx()
Commit 50749f2dd685 ("tcp/udp: Fix memlea
In the Linux kernel, the following vulnerability has been resolved:
net: fix skb leak in __skb_tstamp_tx()
Commit 50749f2dd685 ("tcp/udp: Fix memleaks of sk and zerocopy skbs with
TX timestamp.") added a call to skb_orphan_frags_rx() to fix leaks with
zerocopy skbs. But it ended up adding a leak of its own. When
skb_orphan_frags_rx() fails, the function just returns, leaking the skb
it just cloned. Free it before returning.
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.
OSV
CVE-2023-53716: In the Linux kernel, the following vulnerability has been resolved: net: fix skb leak in __skb_tstamp_tx() Commit 50749f2dd685 ("tcp/udp: Fix memleaks
osv·2025-10-22
CVE-2023-53716 CVE-2023-53716: In the Linux kernel, the following vulnerability has been resolved: net: fix skb leak in __skb_tstamp_tx() Commit 50749f2dd685 ("tcp/udp: Fix memleaks
In the Linux kernel, the following vulnerability has been resolved: net: fix skb leak in __skb_tstamp_tx() Commit 50749f2dd685 ("tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp.") added a call to skb_orphan_frags_rx() to fix leaks with zerocopy skbs. But it ended up adding a leak of its own. When skb_orphan_frags_rx() fails, the function just returns, leaking the skb it just cloned. Free it before returning. This bug was discovered and resolved using Coverity Static Analysis Security Testing (SAST) by Synopsys, Inc.
Red Hat
kernel: Linux kernel: Network subsystem memory leak
vendor_redhat·2025-10-22·CVSS 5.5
CVE-2023-53716 [LOW] CWE-772 kernel: Linux kernel: Network subsystem memory leak
kernel: Linux kernel: Network subsystem memory leak
In the Linux kernel, the following vulnerability has been resolved:
net: fix skb leak in __skb_tstamp_tx()
Commit 50749f2dd685 ("tcp/udp: Fix memleaks of sk and zerocopy skbs with
TX timestamp.") added a call to skb_orphan_frags_rx() to fix leaks with
zerocopy skbs. But it ended up adding a leak of its own. When
skb_orphan_frags_rx() fails, the function just returns, leaking the skb
it just cloned. Free it before returning.
This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.
A flaw was found in the Linux kernel. This vulnerability allows an attacker to cause a denial of service via a memory leak caused by improper handling of skb (socket buffer) cloning in the network subsystem.
Debian
CVE-2023-53716: linux - In the Linux kernel, the following vulnerability has been resolved: net: fix sk...
vendor_debian·2023
CVE-2023-53716 CVE-2023-53716: linux - In the Linux kernel, the following vulnerability has been resolved: net: fix sk...
In the Linux kernel, the following vulnerability has been resolved: net: fix skb leak in __skb_tstamp_tx() Commit 50749f2dd685 ("tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp.") added a call to skb_orphan_frags_rx() to fix leaks with zerocopy skbs. But it ended up adding a leak of its own. When skb_orphan_frags_rx() fails, the function just returns, leaking the skb it just cloned. Free it before returning. This bug was discovered and resolved using Coverity Static Analysis Security Testing (SAST) by Synopsys, Inc.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/58766252f6b2c0487cda6976a53d2bb03ae28e2ahttps://git.kernel.org/stable/c/779332447108545ef04682ea29af5f85c0202aeehttps://git.kernel.org/stable/c/82501f1ead557cbee1c2467654ec109a80334d22https://git.kernel.org/stable/c/8a02fb71d7192ff1a9a47c9d937624966c6e09afhttps://git.kernel.org/stable/c/a594382ec6d0cc8cff5a8bc7e61b54e3858fb243https://git.kernel.org/stable/c/cc18b4685910d5d9de8314bae9c55790701b1811https://git.kernel.org/stable/c/e06841a2abf9c82735cee39e88b1d79464088840https://git.kernel.org/stable/c/f4d928c00254cfc9dd0ee7076f4a59bceec675f4
2025-10-22
Published