CVE-2023-53705

Source
https://cve.org/CVERecord?id=CVE-2023-53705
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53705.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53705
Downstream
Related
Published
2025-10-22T13:23:42.641Z
Modified
2026-03-20T12:33:18.420113Z
Summary
ipv6: Fix out-of-bounds access in ipv6_find_tlv()
Details

In the Linux kernel, the following vulnerability has been resolved:

ipv6: Fix out-of-bounds access in ipv6findtlv()

optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access.

Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53705.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c61a404325093250b676f40ad8f4dd00f3bcab5f
Fixed
59e656d0d4a84ea0ee9a39c6f69160a3effccc94
Fixed
04bf69e3de435d793a203aacc4b774f8f9f2baeb
Fixed
011f47c8b8389154f996f5f69da8efc3a3beefef
Fixed
e5f82688ae10f5f386952e65e941bb8868ee54dc
Fixed
9b92e2d0eb696d7586ba832c8854653b59887da0
Fixed
91dd8aab9c9f193210681b86b6b92840ffe74f0c
Fixed
ae68c0f7edbc9a294094ce03a0aaf45aa489ce40
Fixed
878ecb0897f4737a4c9401f3523fd49589025671

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53705.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.19
Fixed
4.14.316
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.284
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.244
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.181
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.114
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.31
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.3.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53705.json"