CVE-2023-53684

Source
https://cve.org/CVERecord?id=CVE-2023-53684
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53684.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53684
Downstream
Published
2025-10-07T15:21:37.413Z
Modified
2026-07-15T01:49:17.743472460Z
Summary
xfrm: Zero padding when dumping algos and encap
Details

In the Linux kernel, the following vulnerability has been resolved:

xfrm: Zero padding when dumping algos and encap

When copying data to user-space we should ensure that only valid data is copied over. Padding in structures may be filled with random (possibly sensitve) data and should never be given directly to user-space.

This patch fixes the copying of xfrm algorithms and the encap template in xfrm_user so that padding is zeroed.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53684.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c7a5899eb26e2a4d516d53f65b6dd67be2228041
Fixed
0725daaa9a879388ed312110f62dbd5ea2d75f8f
Fixed
5218af4ad5d8948faac19f71583bcd786c3852df
Fixed
1a351e26cc010d6991fbbd5701ac16581372e26f
Fixed
8222d5910dae08213b6d9d4bc9a7f8502855e624

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53684.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.106
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.23
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53684.json"