CVE-2023-53769: Linux

Critical severity, CVSS 9.3. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The encryption algorithms read and write directly to shared unencrypted memory, which may leak information as well as permit the host to tamper with the message integrity. Instead, copy whole messages in or out as needed before doing any computation on them.

Affected products

  • Linux Linux: from 5.19, before 6.1.28 (fixed in 6.1.28); from 6.2, before 6.2.15 (fixed in 6.2.15); from 6.3, before 6.3.2 (fixed in 6.3.2)

Published 2025-12-08. Last modified 2026-08-04.