ipv6: Fix out-of-bounds access in ipv6_find_tlv()
Published Oct 22, 2025
8.2
HIGHCVSS 3.1
EPSS 0.56%
Description
optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access.
Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.19
Unaffected
- ≥ 0, < 2.6.19
- ≥ 4.14.316, ≤ 4.14.*
- ≥ 4.19.284, ≤ 4.19.*
- ≥ 5.10.181, ≤ 5.10.*
- ≥ 5.15.114, ≤ 5.15.*
- ≥ 5.4.244, ≤ 5.4.*
- ≥ 6.1.31, ≤ 6.1.*
- ≥ 6.3.5, ≤ 6.3.*
- 6.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
No data.
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-0:3.10.0-1160.145.1.el7
Fixed · RHSA-2026:0755
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-rt-0:3.10.0-1160.145.1.rt56.1297.el7
Fixed · RHSA-2026:0754
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.el8_10
Fixed · RHSA-2024:3138
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.183.1.el8_2
Fixed · RHSA-2026:1512
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.183.1.el8_4
Fixed · RHSA-2026:0533
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.183.1.el8_4
Fixed · RHSA-2026:0533
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.177.1.el8_6
Fixed · RHSA-2026:1442
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.177.1.el8_6
Fixed · RHSA-2026:1442
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.177.1.el8_6
Fixed · RHSA-2026:1442
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
kernel-0:4.18.0-477.124.1.el8_8
Fixed · RHSA-2026:0532
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.124.1.el8_8
Fixed · RHSA-2026:0532
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-0:5.14.0-70.161.1.el9_0
Fixed · RHSA-2026:0576
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-rt-0:5.14.0-70.161.1.rt21.233.el9_0
Fixed · RHSA-2026:0537
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.154.1.el9_2
Fixed · RHSA-2026:1441
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.154.1.rt14.439.el9_2
Fixed · RHSA-2026:1443
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-0:3.10.0-1160.145.1.el7 | Fixed | RHSA-2026:0755 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-rt-0:3.10.0-1160.145.1.rt56.1297.el7 | Fixed | RHSA-2026:0754 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.el8_10 | Fixed | RHSA-2024:3138 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.183.1.el8_2 | Fixed | RHSA-2026:1512 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.183.1.el8_4 | Fixed | RHSA-2026:0533 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.183.1.el8_4 | Fixed | RHSA-2026:0533 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.177.1.el8_6 | Fixed | RHSA-2026:1442 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.177.1.el8_6 | Fixed | RHSA-2026:1442 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.177.1.el8_6 | Fixed | RHSA-2026:1442 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | kernel-0:4.18.0-477.124.1.el8_8 | Fixed | RHSA-2026:0532 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.124.1.el8_8 | Fixed | RHSA-2026:0532 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-0:5.14.0-70.161.1.el9_0 | Fixed | RHSA-2026:0576 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-rt-0:5.14.0-70.161.1.rt21.233.el9_0 | Fixed | RHSA-2026:0537 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.154.1.el9_2 | Fixed | RHSA-2026:1441 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.154.1.rt14.439.el9_2 | Fixed | RHSA-2026:1443 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The function ipv6_find_tlv() parsed IPv6 extension headers without checking that at least two bytes were available before reading the option length field. An attacker could send a malformed IPv6 packet with a truncated extension header, causing an out-of-bounds read and potential kernel crash or memory fault while parsing. The fix adds a length check (if (len < 2) goto bad;) before accessing the second byte, preventing buffer overrun. This issue is remotely triggerable via network traffic and can lead to kernel panic (DoS) or, in rare cases, information leakage through speculative execution paths.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-53705 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2405713 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-60023 Advisory
- https://git.kernel.org/stable/c/011f47c8b8389154f996f5f69da8efc3a3beefef
- https://git.kernel.org/stable/c/04bf69e3de435d793a203aacc4b774f8f9f2baeb
- https://git.kernel.org/stable/c/59e656d0d4a84ea0ee9a39c6f69160a3effccc94
- https://git.kernel.org/stable/c/878ecb0897f4737a4c9401f3523fd49589025671
- https://git.kernel.org/stable/c/91dd8aab9c9f193210681b86b6b92840ffe74f0c
- https://git.kernel.org/stable/c/9b92e2d0eb696d7586ba832c8854653b59887da0
- https://git.kernel.org/stable/c/ae68c0f7edbc9a294094ce03a0aaf45aa489ce40
- https://git.kernel.org/stable/c/e5f82688ae10f5f386952e65e941bb8868ee54dc
- https://lore.kernel.org/linux-cve-announce/2025102212-CVE-2023-53705-38d9@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53705
- https://www.cve.org/CVERecord?id=CVE-2023-53705
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data