Junglewise Threat Intelligence

CVE-2023-53600: Linux kernel out-of-bounds read in ICMP error generation

CVE-2023-53600 · Severity: critical · CVSS 9.1 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's tunnel code incorrectly processes non-linear network packets when generating ICMP error responses, triggering an out-of-bounds memory read. This flaw can cause system crashes or hangs during tunnel operations, affecting the availability of any system using network tunnels (such as VXLAN). The vulnerability was resolved by using a checksum function that properly handles fragmented packet buffers.

Technical details

The vulnerability is a KASAN-detected out-of-bounds read in the `ip_compute_csum()` function when processing nonlinear socket buffers (skbs) in the PMTU error generation code path (`iptunnel_pmtud_build_icmp()` in `net/ipv4/ip_tunnel_core.c`). The root cause is that `ip_compute_csum()` assumes a contiguous memory buffer but receives a fragmented skb structure. The attack requires sending specially crafted packets through a tunnel (e.g., VXLAN) to trigger the condition. The impact is denial of service via system crash or hang. The fix replaces `ip_compute_csum()` with `csum_fold(skb_checksum())`, which correctly handles nonlinear skbs. The patch was merged upstream in August 2023.

Affected products

  • Linux Linux kernel 5.1 through 6.5 and later stable series

Timeline

  • 2023-08-03: disclosed: Patch commit 6a7ac3d20593865209dceb554d8b3f094c6bd940 authored
  • 2023-08-04: patched: Patch merged upstream
  • 2023-08-16: patched: Backported to stable kernel releases

References

Related threats