CVE-2023-1390: Linux Kernel

High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.

A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100%, causing a denial of service condition.

Affected products

  • Linux Linux Kernel: from 4.3, before 4.9.253 (fixed in 4.9.253); from 4.10, before 4.14.217 (fixed in 4.14.217); from 4.15, before 4.19.170 (fixed in 4.19.170); from 4.20, before 5.4.92 (fixed in 5.4.92); from 5.5, before 5.10.10 (fixed in 5.10.10); version 5.11 only

Published 2023-03-16. Last modified 2026-06-17.