CVE-2023-3773

Aliases:UBUNTU-CVE-2023-3773DEBIAN-CVE-2023-3773CGA-234j-jfrq-fmvqCGA-2962-wm9p-c78gCGA-2cvf-6jgv-85mxCGA-2pjp-3jx6-cvphCGA-32vh-g2p3-mrfpCGA-34jq-8583-fm39CGA-35cg-q2x7-xcr5CGA-3996-pjv7-9f57CGA-3f99-wp99-mcmhCGA-3wxq-vxf9-r2x3CGA-3xc9-74m7-5r8gCGA-468q-8mcv-hj59CGA-4fv2-22gx-7f2vCGA-4rmf-2jmm-chc8CGA-4wc7-p85c-m9wqCGA-53x3-47mc-xw39CGA-57rq-4wjq-xjj5CGA-5c63-7whj-hvw8CGA-5m74-8hxr-h469CGA-5mp8-v833-mpx3CGA-5qfh-66vm-27v6CGA-6366-x3p7-6284CGA-669j-r6vq-g64jCGA-68hr-34wv-8w2wCGA-6cw6-rvf2-h965CGA-6fx8-4hc3-wr3hCGA-6jv7-x2pv-ggqhCGA-6p62-4v3h-w6wrCGA-6rxh-8gr7-5whxCGA-72g3-42q3-xrgmCGA-7mc7-cr9p-3pqgCGA-7mvr-cv2w-wchwCGA-8hj5-47x3-77j6CGA-8hm2-w72q-86pmCGA-8vcj-j2xq-v7wvCGA-9f42-gx7m-q8f5CGA-9hff-p6g5-56ffCGA-9q83-pmgw-84pcCGA-9xq2-28r9-6r22CGA-cch9-q5c4-rqqfCGA-ccvm-wc5h-823jCGA-chw4-3mw2-wx4jCGA-cjfj-79c5-75w9CGA-f2r7-v7rh-9qwxCGA-f2rh-j56q-gqqpCGA-f2x9-j88q-2rfjCGA-f3hg-9gxw-q4xrCGA-fhpr-vhr2-pmg3CGA-fmr4-xfhq-c4p9CGA-g3c9-fxp3-3rgpCGA-g4xr-q959-jr3vCGA-g9cf-55hf-qxcfCGA-gm26-676h-xjf9CGA-gq6j-v3ww-43h7CGA-gvv5-5xj3-w3cmCGA-gvv9-h92j-gj8jCGA-h226-3hjp-8xp8CGA-h39x-q3p7-22g3CGA-h3q4-983c-gg54CGA-h767-22hq-r2rjCGA-h7wq-c3x9-xr74CGA-hg62-67r6-h888CGA-hgj4-37gj-qppqCGA-j935-cp3f-579gCGA-jfh9-h2m9-x7r8CGA-jjcg-qw8m-r599CGA-jq6w-8wp9-6j82CGA-m45m-qjwg-7v5wCGA-m4pm-83j2-2888CGA-m734-f75p-vx4cCGA-m7qq-3fhr-cjgcCGA-m888-5gq8-23j5CGA-mcgx-6gg4-9454CGA-mfv6-ph42-4x76CGA-mjwg-jv8h-7p8fCGA-mvq8-cqcm-3564CGA-p2v8-4q26-g56cCGA-p3w6-xpwm-9m6xCGA-p43x-hrfv-9jxpCGA-p62v-jh39-5x5vCGA-p99j-q25x-cxggCGA-p9w5-q7vj-22c9CGA-pjgc-xc7x-vfjmCGA-pjvw-jmrx-h5h8CGA-pqqf-x2xh-wmj9CGA-pr73-33ph-96q9CGA-prg6-mrh7-jfwfCGA-pwrw-8h2g-c58mCGA-q3p6-5gqc-g8wfCGA-q4fc-mmw3-4x37CGA-q834-vhhx-9899CGA-q9g5-p876-c8pwCGA-qhgf-q39m-fcvfCGA-qm8c-gjpq-8q36CGA-qq3r-8qcf-6g33CGA-qv4j-wp96-xgfpCGA-rh59-2vf9-8jq9CGA-rmgg-97v5-h3j9CGA-rmqq-pj6h-hxv2CGA-v6f4-wmjg-xj7jCGA-vc7p-7xp8-cv37CGA-vg93-rp7x-xhfwCGA-vx3p-j24r-6g9rCGA-w8vg-x45h-6865CGA-w98m-crrc-3r2mCGA-wj3c-7vfr-4jm4CGA-x7gq-vgpr-vqfpCGA-x7xh-8m39-cxwqCGA-xcvv-c8g8-q88cCGA-xgfh-gjc6-v3h9CGA-xgmq-9x53-rr8fCGA-xh5j-q7rm-3qxrCGA-xhv3-cwgh-72x3CGA-xp87-xv9h-hm67CGA-pvpr-cqx8-4cq2CGA-wq56-m5c2-83w7CGA-2f65-87r4-x4rjCGA-566q-8qhp-gj49CGA-64wf-2pmm-fwh5CGA-884c-7v8r-cr3gCGA-993m-q23v-wq5vCGA-c4v6-5hw8-vc58CGA-c88p-vx6h-m47wCGA-g528-q6q3-cf4pCGA-mw7j-69hw-ggj9CGA-r4vh-53p3-j9v9CGA-r4x8-pm77-2mfmCGA-v629-78wq-29j9CGA-v8q8-x2vx-q79gCGA-x93x-8vq9-pg8pCGA-23mp-jmrq-jp32CGA-2969-434p-q5qgCGA-fgc4-gv2q-wx6hCGA-qrhg-63m7-64vvCGA-rpvf-mjm4-h48jCGA-fffc-wv39-wqx9CGA-533m-f646-5hmgCGA-rcwq-vc5h-c5rqCGA-vjqq-pqrr-wffm
Advisory lineage Upstream: 0 Downstream: 15
Modified
Published: 25 Jul 2023, 15:47
Last modified:14 Nov 2025, 14:21

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.25% LOW
0% probability +0.23%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Jul 2023, 15:47
Published
Vulnerability first disclosed
14 Nov 2025, 14:21
Last Modified
Vulnerability information updated

Description

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to userspace.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.25% Percentile: 17%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • chainguardhyperv-daemons-6.18

    < 0

  • chainguardhyperv-daemons-generic

    < 0

  • chainguardlinux-aws-6.12

    < 6.12.65-r0 | < 0

  • chainguardlinux-aws-6.12-boot-installed

    < 0

  • chainguardlinux-aws-6.12-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.12-headers

    < 0

  • chainguardlinux-aws-6.12-modules

    < 0

  • chainguardlinux-aws-6.18

    < 6.18.10-r0 | < 0

  • chainguardlinux-aws-6.18-boot-installed

    < 0

  • chainguardlinux-aws-6.18-fips-boot-installed

    < 0

  • chainguardlinux-aws-6.18-headers

    < 0

  • chainguardlinux-aws-6.18-modules

    < 0

  • chainguardlinux-aws-generic

    < 0 | < 6.18.5-r0

  • chainguardlinux-aws-generic-boot-installed

    < 0

  • chainguardlinux-aws-generic-fips-boot-installed

    < 0

  • chainguardlinux-aws-generic-headers

    < 0

  • chainguardlinux-aws-generic-modules

    < 0

  • chainguardlinux-azure-6.12

    < 0 | < 6.12.65-r1

  • chainguardlinux-azure-6.18

    < 0

  • chainguardlinux-azure-6.18-boot-installed

    < 0

  • chainguardlinux-azure-6.18-fips-boot-installed

    < 0

  • chainguardlinux-azure-6.18-headers

    < 0

  • chainguardlinux-azure-6.18-modules

    < 0

  • chainguardlinux-azure-generic

    < 0 | < 6.18.5-r0

  • chainguardlinux-azure-generic-boot-installed

    < 0

  • chainguardlinux-azure-generic-fips-boot-installed

    < 0

  • chainguardlinux-azure-generic-headers

    < 0

  • chainguardlinux-azure-generic-modules

    < 0

  • chainguardlinux-desktop-6.18

    all

  • chainguardlinux-desktop-6.18-bootc

    all

  • chainguardlinux-desktop-6.18-bootc-boot-installed

    all

  • chainguardlinux-desktop-6.18-headers

    all

  • chainguardlinux-desktop-6.18-modules

    all

  • chainguardlinux-desktop-7.2-bootc

    all

  • chainguardlinux-desktop-7.2-bootc-boot-installed

    all

  • chainguardlinux-desktop-7.2-headers

    all

  • chainguardlinux-desktop-7.2-modules

    all

  • chainguardlinux-firecracker-6.18

    all

  • chainguardlinux-gcp-6.12

    < 0 | < 6.12.65-r0

  • chainguardlinux-gcp-6.18

    < 0 | < 6.18.10-r0

  • chainguardlinux-gcp-6.18-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-fips-boot-installed

    < 0

  • chainguardlinux-gcp-6.18-headers

    < 0

  • chainguardlinux-gcp-6.18-modules

    < 0

  • chainguardlinux-gcp-generic

    < 0 | < 6.18.5-r0

  • chainguardlinux-gcp-generic-boot-installed

    < 0

  • chainguardlinux-gcp-generic-fips-boot-installed

    < 0

  • chainguardlinux-gcp-generic-headers

    < 0

  • chainguardlinux-gcp-generic-modules

    < 0

  • chainguardlinux-qemu-6.12

    < 6.12.71-r0

Showing first 50 affected entries in server-rendered view.

References (18)