In the Linux kernel, the following vulnerability has been resolved:

ipv6: Fix out-of-bounds access in ipv6_find_tlv()

optlen is fetched without checking whether there is more than one byte to parse.
It can lead to out-of-bounds access.

Found by InfoTeCS on behalf of Linux Verification Center
(linuxtesting.org) with SVACE.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse. It can lead to out-of-bounds access. Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
Title ipv6: Fix out-of-bounds access in ipv6_find_tlv()
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2025-10-22T13:23:42.641Z

Reserved: 2025-10-22T13:21:37.346Z

Link: CVE-2023-53705

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-22T14:15:45.080

Modified: 2025-10-22T14:15:45.080

Link: CVE-2023-53705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.