Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53798

12
FAUCET Score

CVE-2023-53798 is a Linux kernel vulnerability in the ethtool interface. It occurs when setting link modes via the legacy IOCTL, where the 'lanes' field in 'struct ethtool_link_ksettings' is not initialized, leading to decisions based on uninitialized memory. This primarily affects drivers like 'tun' that return uninitialized values. The severity is low, as the uninitialized memory is not believed to be leaked to user space, mitigating direct data exposure. The attack vector is through the legacy ethtool IOCTL interface, and the complexity appears moderate, requiring specific conditions to trigger the uninitialized memory access. There is no evidence of active exploitation, exploit code availability, or significant community attention. The CVE has no CVSS score, a very low EPSS score, and a FAUCET Risk Score of 7/100, indicating a minimal threat.

Impacted Technologies

VendorProductVersion(s)CPE
LinuxLinux
5.12CNA affecteddefault affected
LinuxLinux
>= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 6456d80045d6de47734b1a3879c91f72af186529, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 72808c4ab5fd01bf1214195005e15b434bf55cef, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 942a2a0184f7bb1c1ae4bbc556559c86c054b0d2, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 9ad685dbfe7e856bbf17a7177b64676d324d6ed7, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < da81af0ef8092ecacd87fac3229c29e2e0ce39fdCNA affecteddefault unaffected

CVSS Data

CVSS data has not been published for this CVE.

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15

Social Chatter

Media Mentions

No media coverage found for this CVE.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53798Low

kernel: ethtool: Fix uninitialized number of lanes

Dec 9, 2025

References

git.kernel.org / stable/c/6456d80045d6de47734b1a3879c91f72af186529
git.kernel.org / stable/c/72808c4ab5fd01bf1214195005e15b434bf55cef
git.kernel.org / stable/c/942a2a0184f7bb1c1ae4bbc556559c86c054b0d2
git.kernel.org / stable/c/9ad685dbfe7e856bbf17a7177b64676d324d6ed7
git.kernel.org / stable/c/da81af0ef8092ecacd87fac3229c29e2e0ce39fd