Review reviewHigh

CVE-2023-53600

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: tunnels: fix kasan splat when generating ipv4 pmtu error If we try to emit an icmp error in response to a nonliner skb, we get BUG: KASAN: slab-out-of-bounds in ip_compute_csum+0x134/0x220 Read of size 4 at addr ffff88811c50db00 by task iperf3/1691 CPU: 2 PID: 1691 Comm: iperf3 Not tainted 6.5.0-rc3+ #309 [..] kasan_report+0x105/0x140 ip_compute_csum+0x134/0x220 iptunnel_pmtud_build_icmp+0x554/0x1020 skb_tunnel_check_pmtu+0x513/0xb80 vxlan_xmit_one+0x139e/0x2ef0 vxlan_xmit+0x1867/0x2760 dev_hard_start_xmit+0x1ee/0x4f0 br_de...

CVSS
7.1
EPSS
0.27%
19.4% percentile
CISA KEV
Not listed
Published
2025.10.05
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.27%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: tunnels: fix kasan splat when generating ipv4 pmtu error If we try to emit an icmp error in response to a nonliner skb, we get BUG: KASAN: slab-out-of-bounds in ip_compute_csum+0x134/0x220 Read of size 4 at addr ffff88811c50db00 by task iperf3/1691 CPU: 2 PID: 1691 Comm: iperf3 Not tainted 6.5.0-rc3+ #309 [..] kasan_report+0x105/0x140 ip_compute_csum+0x134/0x220 iptunnel_pmtud_build_icmp+0x554/0x1020 skb_tunnel_check_pmtu+0x513/0xb80 vxlan_xmit_one+0x139e/0x2ef0 vxlan_xmit+0x1867/0x2760 dev_hard_start_xmit+0x1ee/0x4f0 br_de...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 5850c391fd7e25662334cb3cbf29a62bcbff1084, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < e95808121953410db8c59f0abfde70ac0d34222c, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < da5f42a6e7485fbb7a6dbd6a2b3045e19e4df5cc, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < fe6a9f7516735be9fdabab00e47ef7a3403a174d, >= 4cb47a8644cc9eb8ec81190a50e79e6530d0297f < 6a7ac3d20593865209dceb554d8b3f094c6bd940, >= 5.9, >= 5.9 < 5.10.191, >= 5.11 < 5.15.127, >= 5.16 < 6.1.46, >= 6.2 < 6.4.11, 6.5
Fixed versions
5.10.191, 5.15.127, 6.1.46, 6.4.11

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2023-53600 — Linux Linux, linux kernel | SECUFOCUS NOW