CVE-2023-53372: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: sctp: fix a potential overflow in sctp_ifwdtsn_skip Currently, when traversing ifwdtsn skips with _sctp_walk_ifwdtsn, it only checks the pos against the end of the chunk. However, the data left for the last pos may be < sizeof(struct sctp_ifwdtsn_skip), and dereference it as struct sctp_ifwdtsn_skip may cause coverflow. This patch fixes it by checking the pos against "the end of the chunk - sizeof(struct sctp_ifwdtsn_skip)" in sctp_ifwdtsn_skip, similar to sctp_fwdtsn_skip.

Affected products

  • Linux Linux Kernel: from 4.16, before 4.19.281 (fixed in 4.19.281); from 4.20, before 5.4.241 (fixed in 5.4.241); from 5.5, before 5.10.178 (fixed in 5.10.178); from 5.11, before 5.15.108 (fixed in 5.15.108); from 5.16, before 6.1.25 (fixed in 6.1.25); from 6.2, before 6.2.12 (fixed in 6.2.12); …

Published 2025-09-18. Last modified 2026-08-04.