SB2025050486 - Resource management error in Linux kernel ipv4
Published: May 4, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-53053)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the ip6erspan_tunnel_xmit() function in net/ipv6/ip6_gre.c, within the erspan_fb_xmit() function in net/ipv4/ip_gre.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5d4172732f0ee1639a361a6cc5c3114bbb397386
- https://git.kernel.org/stable/c/8e50ed774554f93d55426039b27b1e38d7fa64d8
- https://git.kernel.org/stable/c/9c7d6803689c99d55bbb862260d0ba486ff23c0b
- https://git.kernel.org/stable/c/b41f37dbd9cdb60000e3b0dfad6df787591c2265
- https://git.kernel.org/stable/c/b72f453e886af532bde1fd049a2d2421999630d3
- https://git.kernel.org/stable/c/da149daf821a3c05cd04f7c60776c86c5ee9685c
- https://git.kernel.org/stable/c/f8cec30541f5c5cc218e9a32138d45d227727f2f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.177