In the Linux kernel, the following vulnerability has been resolved:
xfrm: Zero padding when dumping algos and encap
When copying data to user-space we should ensure that only valid
data is copied over. Padding in structures may be filled with
random (possibly sensitve) data and should never be given directly
to user-space.
This patch fixes the copying of xfrm algorithms and the encap
template in xfrm_user so that padding is zeroed.
References
Configurations
Configuration 1 (hide)
|
History
03 Feb 2026, 18:13
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| CPE | cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
|
| First Time |
Linux linux Kernel
Linux |
|
| CWE | NVD-CWE-noinfo | |
| References | () https://git.kernel.org/stable/c/0725daaa9a879388ed312110f62dbd5ea2d75f8f - Patch | |
| References | () https://git.kernel.org/stable/c/1a351e26cc010d6991fbbd5701ac16581372e26f - Patch | |
| References | () https://git.kernel.org/stable/c/5218af4ad5d8948faac19f71583bcd786c3852df - Patch | |
| References | () https://git.kernel.org/stable/c/8222d5910dae08213b6d9d4bc9a7f8502855e624 - Patch |
Information
Published : 2025-10-07 16:15
Updated : 2026-02-03 18:13
NVD link : CVE-2023-53684
Mitre link : CVE-2023-53684
CVE.ORG link : CVE-2023-53684
JSON object : View
Products Affected
linux
- linux_kernel
CWE
