Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53333

23
FAUCET Score

CVE-2023-53333 is a stack-out-of-bounds read vulnerability in the Linux kernel's netfilter conntrack DCCP module. It arises because the nf_conntrack_dccp_packet() function reads past a small stack buffer when processing DCCP packet headers. This vulnerability has a CVSS score of 7.1 (HIGH), indicating a local attack vector with low complexity, potentially leading to high impact on confidentiality and availability. While no active exploits, public exploit code, or significant community discussion have been observed, the vulnerability is addressed by increasing the stack buffer size and validating header data.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.26, < 5.4.251CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.188CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.39CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.3.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 17th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-362.8.1.el9_3
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53333Moderate

kernel: netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one

Sep 16, 2025

References

git.kernel.org / stable/c/26bd1f210d3783a691052c51d76bb8a8bbd24c67
Patch
git.kernel.org / stable/c/337fdce450637ea663bc816edc2ba81e5cdad02e
Patch
git.kernel.org / stable/c/5c618daa5038712c4a4ef8923905a2ea1b8836a1
Patch
git.kernel.org / stable/c/8c0980493beed3a80d6329c44ab293dc8c032927
Patch
git.kernel.org / stable/c/9bdcda7abaf22f6453e5b5efb7eb4e524095d5d8
Patch
git.kernel.org / stable/c/c052797ac36813419ad3bfa54cb8615db4b41f15
Patch
git.kernel.org / stable/c/ff0a3a7d52ff7282dbd183e7fc29a1fe386b0c30
Patch