CVE-2023-23454: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 2.6.12, up to and including 6.1.4

Published 2023-01-12. Last modified 2026-06-17.