CVE-2023-53179

HIGH

Linux Kernel 4.4.165-4.4.9999 - Out-of-bounds Write in ip_set_hash_netportnet

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c The missing IP_SET_HASH_WITH_NET0 macro in ip_set_hash_netportnet can lead to the use of wrong `CIDR_POS(c)` for calculating array offsets, which can lead to integer underflow. As a result, it leads to slab out-of-bound access. This patch adds back the IP_SET_HASH_WITH_NET0 macro to ip_set_hash_netportnet to address the issue.

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 5.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (28)
Linux/Linux < 4.20
Linux/Linux 0d5d0b5c41f766355f2b42c47d13ea001f754c7d - 7935b636dd693dfe4483cfef4a1e91366c8103fa
Linux/Linux 186642845b02e1a7944ef33c3a3ac41eba77517f
Linux/Linux 4.14.326 - 4.14.*
Linux/Linux 4.14.84 - 4.14.326
Linux/Linux 4.19.295 - 4.19.*
Linux/Linux 4.19.5 - 4.19.295
Linux/Linux 4.20
Linux/Linux 4.4.165 - 4.5
Linux/Linux 4.9.141 - 4.10
... and 18 more
Published Sep 15, 2025
Tracked Since Feb 18, 2026