CVE-2023-53798 is a Linux kernel vulnerability in the ethtool interface. It occurs when setting link modes via the legacy IOCTL, where the 'lanes' field in 'struct ethtool_link_ksettings' is not initialized, leading to decisions based on uninitialized memory. This primarily affects drivers like 'tun' that return uninitialized values. The severity is low, as the uninitialized memory is not believed to be leaked to user space, mitigating direct data exposure. The attack vector is through the legacy ethtool IOCTL interface, and the complexity appears moderate, requiring specific conditions to trigger the uninitialized memory access. There is no evidence of active exploitation, exploit code availability, or significant community attention. The CVE has no CVSS score, a very low EPSS score, and a FAUCET Risk Score of 7/100, indicating a minimal threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.12CNA affecteddefault affected | |
| Linux | Linux | >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 6456d80045d6de47734b1a3879c91f72af186529, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 72808c4ab5fd01bf1214195005e15b434bf55cef, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 942a2a0184f7bb1c1ae4bbc556559c86c054b0d2, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < 9ad685dbfe7e856bbf17a7177b64676d324d6ed7, >= 012ce4dd3102a0f4d80167de343e9d44b257c1b8, < da81af0ef8092ecacd87fac3229c29e2e0ce39fdCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.