目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-53821— Linux kernel 安全漏洞

AI 预测 6.6 利用难度: 中等 EPSS 0.23% · P14

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinuxf855691975bb06373a98711e4cfe2c224244b536< 0f0ab8d52ee0062b28367dea23c29e254a26d7dbaffected
f855691975bb06373a98711e4cfe2c224244b536< fa6c6c04f6c9b21b315023f487e5a07ae7fcf647affected
f855691975bb06373a98711e4cfe2c224244b536< eb47e612e59c358c3968a92f90dd36c78c9a2106affected
f855691975bb06373a98711e4cfe2c224244b536< ec23b25e5687dbd644c0f57bcb6af22dd5a6dd36affected
f855691975bb06373a98711e4cfe2c224244b536< a1639a82ce14af76b6419778d343ccbff86ee626affected
f855691975bb06373a98711e4cfe2c224244b536< 55ad2309205cc00c585344374c7472420e1b2c12affected
f855691975bb06373a98711e4cfe2c224244b536< c070688bfbe7759e61e697e421b2a331b0dd74bcaffected
f855691975bb06373a98711e4cfe2c224244b536< 9fd41f1ba638938c9a1195d09bc6fa3be2712f25affected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-53821 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ip6_vti: fix slab-use-after-free in decode_session6
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix slab-use-after-free in decode_session6 When ipv6_vti device is set to the qdisc of the sfb type, the cb field of the sent skb may be modified during enqueuing. Then, slab-use-after-free may occur when ipv6_vti device sends IPv6 packets. The stack information is as follows: BUG: KASAN: slab-use-after-free in decode_session6+0x103f/0x1890 Read of size 1 at addr ffff88802e08edc2 by task swapper/0/0 CPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.4.0-next-20230707-00001-g84e2cad7f979 #410 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-1.fc33 04/01/2014 Call Trace: <IRQ> dump_stack_lvl+0xd9/0x150 print_address_description.constprop.0+0x2c/0x3c0 kasan_report+0x11d/0x130 decode_session6+0x103f/0x1890 __xfrm_decode_session+0x54/0xb0 vti6_tnl_xmit+0x3e6/0x1ee0 dev_hard_start_xmit+0x187/0x700 sch_direct_xmit+0x1a3/0xc30 __qdisc_run+0x510/0x17a0 __dev_queue_xmit+0x2215/0x3b10 neigh_connected_output+0x3c2/0x550 ip6_finish_output2+0x55a/0x1550 ip6_finish_output+0x6b9/0x1270 ip6_output+0x1f1/0x540 ndisc_send_skb+0xa63/0x1890 ndisc_send_rs+0x132/0x6f0 addrconf_rs_timer+0x3f1/0x870 call_timer_fn+0x1a0/0x580 expire_timers+0x29b/0x4b0 run_timer_softirq+0x326/0x910 __do_softirq+0x1d4/0x905 irq_exit_rcu+0xb7/0x120 sysvec_apic_timer_interrupt+0x97/0xc0 </IRQ> Allocated by task 9176: kasan_save_stack+0x22/0x40 kasan_set_track+0x25/0x30 __kasan_slab_alloc+0x7f/0x90 kmem_cache_alloc_node+0x1cd/0x410 kmalloc_reserve+0x165/0x270 __alloc_skb+0x129/0x330 netlink_sendmsg+0x9b1/0xe30 sock_sendmsg+0xde/0x190 ____sys_sendmsg+0x739/0x920 ___sys_sendmsg+0x110/0x1b0 __sys_sendmsg+0xf7/0x1c0 do_syscall_64+0x39/0xb0 entry_SYSCALL_64_after_hwframe+0x63/0xcd Freed by task 9176: kasan_save_stack+0x22/0x40 kasan_set_track+0x25/0x30 kasan_save_free_info+0x2b/0x40 ____kasan_slab_free+0x160/0x1c0 slab_free_freelist_hook+0x11b/0x220 kmem_cache_free+0xf0/0x490 skb_free_head+0x17f/0x1b0 skb_release_data+0x59c/0x850 consume_skb+0xd2/0x170 netlink_unicast+0x54f/0x7f0 netlink_sendmsg+0x926/0xe30 sock_sendmsg+0xde/0x190 ____sys_sendmsg+0x739/0x920 ___sys_sendmsg+0x110/0x1b0 __sys_sendmsg+0xf7/0x1c0 do_syscall_64+0x39/0xb0 entry_SYSCALL_64_after_hwframe+0x63/0xcd The buggy address belongs to the object at ffff88802e08ed00 which belongs to the cache skbuff_small_head of size 640 The buggy address is located 194 bytes inside of freed 640-byte region [ffff88802e08ed00, ffff88802e08ef80) As commit f855691975bb ("xfrm6: Fix the nexthdr offset in _decode_session6.") showed, xfrm_decode_session was originally intended only for the receive path. IP6CB(skb)->nhoff is not set during transmission. Therefore, set the cb field in the skb to 0 before sending packets.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ip6_vti设备在发送IPv6包时可能触发释放后重用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux f855691975bb06373a98711e4cfe2c224244b536 ~ 0f0ab8d52ee0062b28367dea23c29e254a26d7db -
LinuxLinux 3.19 -

二、漏洞 CVE-2023-53821 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-53821 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-12-09 · 共 152 条

CVE-2025-403439.8 CRITICALLinux kernel 安全漏洞
CVE-2023-537949.8 CRITICALLinux kernel 安全漏洞
CVE-2022-506669.8 CRITICALLinux kernel 安全漏洞
CVE-2023-538278.8 HIGHLinux kernel 安全漏洞
CVE-2023-537858.8 HIGHLinux kernel 安全漏洞
CVE-2023-538228.8 HIGHLinux kernel 安全漏洞
CVE-2025-403368.8 HIGHLinux kernel 安全漏洞
CVE-2025-403428.8 HIGHLinux kernel 安全漏洞
CVE-2025-403288.8 HIGHLinux kernel 安全漏洞
CVE-2023-538518.4 HIGHLinux kernel 安全漏洞
CVE-2025-403378.2 HIGHLinux kernel 安全漏洞
CVE-2022-506568.1 HIGHLinux kernel 安全漏洞
CVE-2023-538038.1 HIGHLinux kernel 安全漏洞
CVE-2023-538047.8 HIGHLinux kernel 安全漏洞
CVE-2023-538197.8 HIGHLinux kernel 安全漏洞
CVE-2023-538167.8 HIGHLinux kernel 安全漏洞
CVE-2023-538007.8 HIGHLinux kernel 安全漏洞
CVE-2023-537907.8 HIGHLinux kernel 安全漏洞
CVE-2023-537957.8 HIGHLinux kernel 安全漏洞
CVE-2023-538107.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 152 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53821

暂无评论


发表评论