CVE-2023-53705: Linux
High severity, CVSS 8.2. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
Affected products
- Linux Linux: from 2.6.19, before 4.14.316 (fixed in 4.14.316); from 4.15, before 4.19.284 (fixed in 4.19.284); from 4.20, before 5.4.244 (fixed in 5.4.244); from 5.5, before 5.10.181 (fixed in 5.10.181); from 5.11, before 5.15.114 (fixed in 5.15.114); from 5.16, before 6.1.31 (fixed in 6.1.31); …
Published 2025-10-22. Last modified 2026-08-04.