We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-53033

netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits



Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits If the offset + length goes over the ethernet + vlan header, then the length is adjusted to copy the bytes that are within the boundaries of the vlan_ethhdr scratchpad area. The remaining bytes beyond ethernet + vlan header are copied directly from the skbuff data area. Fix incorrect arithmetic operator: subtract, not add, the size of the vlan header in case of double-tagged packets to adjust the length accordingly to address CVE-2023-0179.

Reserved 2025-03-27 | Published 2025-03-27 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

f6ae9f120dada00abfb47313364c35118469455f before 550efeff989b041f3746118c0ddd863c39ddc1aa
affected

f6ae9f120dada00abfb47313364c35118469455f before a8acfe2c6fb99f9375a9325807a179cd8c32e6e3
affected

f6ae9f120dada00abfb47313364c35118469455f before 76ef74d4a379faa451003621a84e3498044e7aa3
affected

f6ae9f120dada00abfb47313364c35118469455f before 696e1a48b1a1b01edad542a1ef293665864a4dd0
affected

Default status
affected

5.5
affected

Any version before 5.5
unaffected

5.10.164
unaffected

5.15.89
unaffected

6.1.7
unaffected

6.2
unaffected

References

git.kernel.org/...c/550efeff989b041f3746118c0ddd863c39ddc1aa

git.kernel.org/...c/a8acfe2c6fb99f9375a9325807a179cd8c32e6e3

git.kernel.org/...c/76ef74d4a379faa451003621a84e3498044e7aa3

git.kernel.org/...c/696e1a48b1a1b01edad542a1ef293665864a4dd0

cve.org (CVE-2023-53033)

nvd.nist.gov (CVE-2023-53033)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-53033

Support options

Helpdesk Chat, Email, Knowledgebase