-

CVE-2023-53705

In the Linux kernel, the following vulnerability has been resolved:

ipv6: Fix out-of-bounds access in ipv6_find_tlv()

optlen is fetched without checking whether there is more than one byte to parse.
It can lead to out-of-bounds access.

Found by InfoTeCS on behalf of Linux Verification Center
(linuxtesting.org) with SVACE.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 59e656d0d4a84ea0ee9a39c6f69160a3effccc94
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
Version < 04bf69e3de435d793a203aacc4b774f8f9f2baeb
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
Version < 011f47c8b8389154f996f5f69da8efc3a3beefef
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
Version < e5f82688ae10f5f386952e65e941bb8868ee54dc
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
Version < 9b92e2d0eb696d7586ba832c8854653b59887da0
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
Version < 91dd8aab9c9f193210681b86b6b92840ffe74f0c
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
Version < ae68c0f7edbc9a294094ce03a0aaf45aa489ce40
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
Version < 878ecb0897f4737a4c9401f3523fd49589025671
Version c61a404325093250b676f40ad8f4dd00f3bcab5f
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.19
Status affected
Version < 2.6.19
Version 0
Status unaffected
Version <= 4.14.*
Version 4.14.316
Status unaffected
Version <= 4.19.*
Version 4.19.284
Status unaffected
Version <= 5.4.*
Version 5.4.244
Status unaffected
Version <= 5.10.*
Version 5.10.181
Status unaffected
Version <= 5.15.*
Version 5.15.114
Status unaffected
Version <= 6.1.*
Version 6.1.31
Status unaffected
Version <= 6.3.*
Version 6.3.5
Status unaffected
Version <= *
Version 6.4
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.096
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String