Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53559

24
FAUCET Score

CVE-2023-53559 is a high-severity slab-use-after-free vulnerability in the Linux kernel's ip_vti module, specifically affecting IPv6 packet transmission when the ip_vti device is configured with a sfb type qdisc. This flaw can lead to a system crash or potentially arbitrary code execution due to memory corruption. The vulnerability has a CVSS score of 7.8 (High), indicating that a local attacker with low privileges can exploit it with low attack complexity, resulting in high impact to confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.19.1, < 4.14.324CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.293CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.255CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.192CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.128CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 17th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-427.13.1.el9_4
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53559Moderate

kernel: ip_vti: fix potential slab-use-after-free in decode_session6

Oct 4, 2025

References

git.kernel.org / stable/c/0b4d69539fdea138af2befe08893850c89248068
Patch
git.kernel.org / stable/c/2b05bf5dc437f7891dd409a3eaf5058459391c7a
Patch
git.kernel.org / stable/c/6018a266279b1a75143c7c0804dd08a5fc4c3e0b
Patch
git.kernel.org / stable/c/78e397a43e1c47321a4679cc49a6c4530bf820b9
Patch
git.kernel.org / stable/c/7dfe23659f3677c08a60a0056cda2d91a79c15ca
Patch
git.kernel.org / stable/c/82fb41c5de243e7dfa90f32ca58e35adaff56c1d
Patch
git.kernel.org / stable/c/d34c30442d5e53a33cde79ca163320dbe2432cbd
Patch
git.kernel.org / stable/c/e1e04cc2ef2c0c0866c19f5627149a76c2baae32
Patch