A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Codeready Linux Builder Eus Subscribe
Codeready Linux Builder Eus For Power Little Endian Eus Subscribe
Codeready Linux Builder For Arm64 Eus Subscribe
Codeready Linux Builder For Ibm Z Systems Eus Subscribe
Enterprise Linux Subscribe
Enterprise Linux Eus Subscribe
Enterprise Linux For Arm 64 Eus Subscribe
Enterprise Linux For Ibm Z Systems Eus Subscribe
Enterprise Linux For Power Little Endian Eus Subscribe
Enterprise Linux For Real Time Subscribe
Enterprise Linux For Real Time For Nfv Subscribe
Enterprise Linux Server Aus Subscribe
Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Subscribe
Enterprise Linux Server Tus Subscribe
Logging Subscribe
Rhel Eus Subscribe
Rhev Hypervisor Subscribe
Virtualization Host Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3841-1 linux-5.10 security update
EUVD EUVD EUVD-2023-58766 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.
Ubuntu USN Ubuntu USN USN-6818-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6818-2 Linux kernel (ARM laptop) vulnerabilities
Ubuntu USN Ubuntu USN USN-6818-3 Linux kernel (NVIDIA) vulnerabilities
Ubuntu USN Ubuntu USN USN-6818-4 Linux kernel (HWE) vulnerabilities
Ubuntu USN Ubuntu USN USN-6819-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6819-2 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-6819-3 Linux kernel (OEM) vulnerabilities
Ubuntu USN Ubuntu USN USN-6819-4 Linux kernel (Oracle) vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

To mitigate this issue, prevent module nvmet-tcp from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

History

Tue, 04 Nov 2025 19:30:00 +0000


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00034}

epss

{'score': 0.00026}


Fri, 22 Nov 2024 12:00:00 +0000


Fri, 15 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-06T21:45:16.229Z

Reserved: 2023-12-05T20:50:27.727Z

Link: CVE-2023-6535

cve-icon Vulnrichment

Updated: 2025-11-04T18:22:00.240Z

cve-icon NVD

Status : Modified

Published: 2024-02-07T21:15:08.530

Modified: 2025-11-04T19:16:24.490

Link: CVE-2023-6535

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-12-11T00:00:00Z

Links: CVE-2023-6535 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses