CVE-2023-53798 — Use of Uninitialized Resource in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 89.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9
Description
In the Linux kernel, the following vulnerability has been resolved:
ethtool: Fix uninitialized number of lanes
It is not possible to set the number of lanes when setting link modes
using the legacy IOCTL ethtool interface. Since 'struct
ethtool_link_ksettings' is not initialized in this path, drivers receive
an uninitialized number of lanes in 'struct
ethtool_link_ksettings::lanes'.
When this information is later queried from drivers, it results in the
ethtool code making decisions based on u…
Affected Packages4 packages
▶CVEListV5linux/linux012ce4dd3102a0f4d80167de343e9d44b257c1b8 — da81af0ef8092ecacd87fac3229c29e2e0ce39fd+5
🔴Vulnerability Details
3OSV▶
CVE-2023-53798: In the Linux kernel, the following vulnerability has been resolved: ethtool: Fix uninitialized number of lanes It is not possible to set the number of↗2025-12-09
GHSA▶
GHSA-rhrj-6hqh-9pgr: In the Linux kernel, the following vulnerability has been resolved:
ethtool: Fix uninitialized number of lanes
It is not possible to set the number↗2025-12-09