Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53265

23
FAUCET Score

CVE-2023-53265 is a slab-out-of-bounds vulnerability in the Linux kernel's UBI (Unsorted Block Images) subsystem. It occurs when the VID header offset plus its size exceeds the allocated memory area, leading to a memory corruption during CRC32 calculations. This flaw affects various versions of the Linux kernel. The vulnerability has a CVSSv3.1 score of 7.1 (High), indicating a local attack vector with low attack complexity, requiring low privileges. A successful exploit could lead to high impact on confidentiality and availability, potentially allowing an attacker to read sensitive kernel memory or cause a system crash. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention from the broader security community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.22, < 4.14.308CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.235CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.173CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.100CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 21st percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53265Low

kernel: ubi: ensure that VID header offset + VID header size <= alloc, size

Sep 16, 2025

References

git.kernel.org / stable/c/1b42b1a36fc946f0d7088425b90d491b4257ca3e
Patch
git.kernel.org / stable/c/61aeba0e4b4124cfe3c5427feaf29c626dfa89e5
Patch
git.kernel.org / stable/c/61e04db3bec87f7dd10074296deb7d083e2ccade
Patch
git.kernel.org / stable/c/701bb3ed5a88a73ebbe1266895bdeff065226dca
Patch
git.kernel.org / stable/c/771e207a839a29ba943e89f473b0fecd16089e2e
Patch
git.kernel.org / stable/c/846bfba34175c23b13cc2023c2d67b96e8c14c43
Patch
git.kernel.org / stable/c/e1b73fe4f4c6bb80755eb4bf4b867a8fd8b1a7fe
Patch
git.kernel.org / stable/c/f7adb740f97b6fa84e658892dcb08e37a31a4e77
Patch