[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2023-53821":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T14:53:31.930Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":14,"duplicates":55,"related":56,"reserved_at":9,"published_at":65,"modified_at":66,"state":67,"summary":68,"references_raw":72,"kevs":107,"epss":108,"epss_history":111,"metrics":383,"affected":384},"CVE-2023-53821","In the Linux kernel, the following vulnerability has been resolved:\n\nip6_vti: fix slab-use-after-free in decode_session6\n\nWhen ipv6_vti device is set to the qdisc of the sfb type, the cb field\nof the sent skb may be modified during enqueuing. Then,\nslab-use-after-free may occur when ipv6_vti device sends IPv6 packets.\n\nThe stack information is as follows:\nBUG: KASAN: slab-use-after-free in decode_session6+0x103f/0x1890\nRead of size 1 at addr ffff88802e08edc2 by task swapper/0/0\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.4.0-next-20230707-00001-g84e2cad7f979 #410\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-1.fc33 04/01/2014\nCall Trace:\n\u003CIRQ>\ndump_stack_lvl+0xd9/0x150\nprint_address_description.constprop.0+0x2c/0x3c0\nkasan_report+0x11d/0x130\ndecode_session6+0x103f/0x1890\n__xfrm_decode_session+0x54/0xb0\nvti6_tnl_xmit+0x3e6/0x1ee0\ndev_hard_start_xmit+0x187/0x700\nsch_direct_xmit+0x1a3/0xc30\n__qdisc_run+0x510/0x17a0\n__dev_queue_xmit+0x2215/0x3b10\nneigh_connected_output+0x3c2/0x550\nip6_finish_output2+0x55a/0x1550\nip6_finish_output+0x6b9/0x1270\nip6_output+0x1f1/0x540\nndisc_send_skb+0xa63/0x1890\nndisc_send_rs+0x132/0x6f0\naddrconf_rs_timer+0x3f1/0x870\ncall_timer_fn+0x1a0/0x580\nexpire_timers+0x29b/0x4b0\nrun_timer_softirq+0x326/0x910\n__do_softirq+0x1d4/0x905\nirq_exit_rcu+0xb7/0x120\nsysvec_apic_timer_interrupt+0x97/0xc0\n\u003C/IRQ>\nAllocated by task 9176:\nkasan_save_stack+0x22/0x40\nkasan_set_track+0x25/0x30\n__kasan_slab_alloc+0x7f/0x90\nkmem_cache_alloc_node+0x1cd/0x410\nkmalloc_reserve+0x165/0x270\n__alloc_skb+0x129/0x330\nnetlink_sendmsg+0x9b1/0xe30\nsock_sendmsg+0xde/0x190\n____sys_sendmsg+0x739/0x920\n___sys_sendmsg+0x110/0x1b0\n__sys_sendmsg+0xf7/0x1c0\ndo_syscall_64+0x39/0xb0\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\nFreed by task 9176:\nkasan_save_stack+0x22/0x40\nkasan_set_track+0x25/0x30\nkasan_save_free_info+0x2b/0x40\n____kasan_slab_free+0x160/0x1c0\nslab_free_freelist_hook+0x11b/0x220\nkmem_cache_free+0xf0/0x490\nskb_free_head+0x17f/0x1b0\nskb_release_data+0x59c/0x850\nconsume_skb+0xd2/0x170\nnetlink_unicast+0x54f/0x7f0\nnetlink_sendmsg+0x926/0xe30\nsock_sendmsg+0xde/0x190\n____sys_sendmsg+0x739/0x920\n___sys_sendmsg+0x110/0x1b0\n__sys_sendmsg+0xf7/0x1c0\ndo_syscall_64+0x39/0xb0\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\nThe buggy address belongs to the object at ffff88802e08ed00\nwhich belongs to the cache skbuff_small_head of size 640\nThe buggy address is located 194 bytes inside of\nfreed 640-byte region [ffff88802e08ed00, ffff88802e08ef80)\n\nAs commit f855691975bb (\"xfrm6: Fix the nexthdr offset in\n_decode_session6.\") showed, xfrm_decode_session was originally intended\nonly for the receive path. IP6CB(skb)->nhoff is not set during\ntransmission. Therefore, set the cb field in the skb to 0 before\nsending packets.",null,[],[],[],[],[15,17,19,21,23,25,27,29,31,33,35,37,39,41,43,45,47,49,51,53],{"_key":16},"SUSE-SU-2026:0278-1",{"_key":18},"SUSE-SU-2026:0281-1",{"_key":20},"SUSE-SU-2026:0315-1",{"_key":22},"SUSE-SU-2026:20477-1",{"_key":24},"SUSE-SU-2026:20498-1",{"_key":26},"SUSE-SU-2026:0293-1",{"_key":28},"SUSE-SU-2026:20845-1",{"_key":30},"SUSE-SU-2026:20876-1",{"_key":32},"RHSA-2026:3268",{"_key":34},"RHSA-2026:3277",{"_key":36},"RHSA-2026:3293",{"_key":38},"RHSA-2026:3375",{"_key":40},"RHSA-2026:3388",{"_key":42},"RHSA-2026:3360",{"_key":44},"DEBIAN-CVE-2023-53821",{"_key":46},"RHSA-2026:3267",{"_key":48},"RHSA-2026:3358",{"_key":50},"UBUNTU-CVE-2023-53821",{"_key":52},"RHSA-2024:2394",{"_key":54},"RHSA-2024:3138",[],[57,58,59,60,61,62,63,64],{"_key":16},{"_key":18},{"_key":20},{"_key":22},{"_key":24},{"_key":26},{"_key":28},{"_key":30},"2025-12-09T01:29:34.073Z","2026-05-11T19:52:11.135Z","Deferred",{"cisa_kev":69,"cisa_ransomware":69,"cisa_vendor":9,"epss_severity":70,"epss_score":71,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":67},false,"low",0.0004,[73,79,83,87,91,95,99,103],{"url":74,"sources":75,"tags":78},"https://git.kernel.org/stable/c/0f0ab8d52ee0062b28367dea23c29e254a26d7db",[76,77],"cve.org","nvd",[],{"url":80,"sources":81,"tags":82},"https://git.kernel.org/stable/c/fa6c6c04f6c9b21b315023f487e5a07ae7fcf647",[76,77],[],{"url":84,"sources":85,"tags":86},"https://git.kernel.org/stable/c/eb47e612e59c358c3968a92f90dd36c78c9a2106",[76,77],[],{"url":88,"sources":89,"tags":90},"https://git.kernel.org/stable/c/ec23b25e5687dbd644c0f57bcb6af22dd5a6dd36",[76,77],[],{"url":92,"sources":93,"tags":94},"https://git.kernel.org/stable/c/a1639a82ce14af76b6419778d343ccbff86ee626",[76,77],[],{"url":96,"sources":97,"tags":98},"https://git.kernel.org/stable/c/55ad2309205cc00c585344374c7472420e1b2c12",[76,77],[],{"url":100,"sources":101,"tags":102},"https://git.kernel.org/stable/c/c070688bfbe7759e61e697e421b2a331b0dd74bc",[76,77],[],{"url":104,"sources":105,"tags":106},"https://git.kernel.org/stable/c/9fd41f1ba638938c9a1195d09bc6fa3be2712f25",[76,77],[],[],{"date":109,"score":71,"percentile":110},"2026-06-04",0.12387,[112,116,119,122,125,128,131,135,138,141,144,147,150,153,156,159,161,164,167,170,173,176,179,182,185,188,191,194,197,199,202,205,208,212,215,218,221,224,227,230,233,236,239,242,245,248,251,254,257,260,263,266,269,272,275,278,281,284,287,290,293,296,299,302,305,308,311,314,317,321,324,327,330,333,336,339,342,345,348,351,354,357,360,363,366,369,372,375,377,380],{"date":113,"score":114,"percentile":115},"2025-12-09",0.00024,0.05787,{"date":117,"score":114,"percentile":118},"2025-12-10",0.05855,{"date":120,"score":114,"percentile":121},"2025-12-11",0.05851,{"date":123,"score":114,"percentile":124},"2025-12-12",0.05874,{"date":126,"score":114,"percentile":127},"2025-12-13",0.05918,{"date":129,"score":114,"percentile":130},"2025-12-14",0.05883,{"date":132,"score":133,"percentile":134},"2025-12-15",0.00032,0.08737,{"date":136,"score":133,"percentile":137},"2025-12-16",0.08762,{"date":139,"score":133,"percentile":140},"2025-12-17",0.08845,{"date":142,"score":133,"percentile":143},"2025-12-18",0.08904,{"date":145,"score":133,"percentile":146},"2025-12-19",0.08918,{"date":148,"score":133,"percentile":149},"2025-12-20",0.08909,{"date":151,"score":133,"percentile":152},"2025-12-21",0.08852,{"date":154,"score":133,"percentile":155},"2025-12-22",0.08818,{"date":157,"score":133,"percentile":158},"2025-12-23",0.08804,{"date":160,"score":133,"percentile":155},"2025-12-24",{"date":162,"score":133,"percentile":163},"2025-12-25",0.08889,{"date":165,"score":133,"percentile":166},"2025-12-26",0.08888,{"date":168,"score":133,"percentile":169},"2025-12-27",0.08865,{"date":171,"score":133,"percentile":172},"2025-12-28",0.0889,{"date":174,"score":133,"percentile":175},"2025-12-29",0.08863,{"date":177,"score":133,"percentile":178},"2025-12-30",0.08859,{"date":180,"score":133,"percentile":181},"2025-12-31",0.08905,{"date":183,"score":133,"percentile":184},"2026-01-01",0.0897,{"date":186,"score":133,"percentile":187},"2026-01-02",0.08972,{"date":189,"score":133,"percentile":190},"2026-01-03",0.08963,{"date":192,"score":133,"percentile":193},"2026-01-04",0.08894,{"date":195,"score":133,"percentile":196},"2026-01-05",0.08862,{"date":198,"score":133,"percentile":140},"2026-01-06",{"date":200,"score":133,"percentile":201},"2026-01-07",0.08876,{"date":203,"score":133,"percentile":204},"2026-01-08",0.0895,{"date":206,"score":133,"percentile":207},"2026-01-09",0.08959,{"date":209,"score":210,"percentile":211},"2026-01-10",0.00035,0.09991,{"date":213,"score":210,"percentile":214},"2026-01-11",0.09942,{"date":216,"score":210,"percentile":217},"2026-01-12",0.09919,{"date":219,"score":210,"percentile":220},"2026-01-13",0.09881,{"date":222,"score":210,"percentile":223},"2026-01-14",0.09934,{"date":225,"score":210,"percentile":226},"2026-01-15",0.09948,{"date":228,"score":210,"percentile":229},"2026-01-16",0.09984,{"date":231,"score":210,"percentile":232},"2026-01-17",0.10001,{"date":234,"score":210,"percentile":235},"2026-01-18",0.09962,{"date":237,"score":210,"percentile":238},"2026-01-19",0.09914,{"date":240,"score":210,"percentile":241},"2026-01-20",0.09888,{"date":243,"score":210,"percentile":244},"2026-01-21",0.09854,{"date":246,"score":210,"percentile":247},"2026-01-22",0.0984,{"date":249,"score":210,"percentile":250},"2026-01-23",0.09937,{"date":252,"score":210,"percentile":253},"2026-01-24",0.09992,{"date":255,"score":210,"percentile":256},"2026-01-25",0.09953,{"date":258,"score":210,"percentile":259},"2026-01-26",0.09908,{"date":261,"score":210,"percentile":262},"2026-01-27",0.09891,{"date":264,"score":210,"percentile":265},"2026-01-28",0.09869,{"date":267,"score":210,"percentile":268},"2026-01-29",0.09842,{"date":270,"score":210,"percentile":271},"2026-01-30",0.09853,{"date":273,"score":210,"percentile":274},"2026-01-31",0.0987,{"date":276,"score":210,"percentile":277},"2026-02-01",0.0988,{"date":279,"score":210,"percentile":280},"2026-02-02",0.09837,{"date":282,"score":210,"percentile":283},"2026-02-03",0.09813,{"date":285,"score":210,"percentile":286},"2026-02-04",0.09832,{"date":288,"score":210,"percentile":289},"2026-02-05",0.0989,{"date":291,"score":210,"percentile":292},"2026-02-06",0.09917,{"date":294,"score":210,"percentile":295},"2026-02-07",0.09943,{"date":297,"score":210,"percentile":298},"2026-02-08",0.09931,{"date":300,"score":210,"percentile":301},"2026-02-09",0.09886,{"date":303,"score":210,"percentile":304},"2026-02-10",0.09844,{"date":306,"score":210,"percentile":307},"2026-02-11",0.09892,{"date":309,"score":210,"percentile":310},"2026-02-12",0.09925,{"date":312,"score":210,"percentile":313},"2026-02-13",0.09922,{"date":315,"score":210,"percentile":316},"2026-02-14",0.09904,{"date":318,"score":319,"percentile":320},"2026-02-15",0.00036,0.10565,{"date":322,"score":319,"percentile":323},"2026-02-16",0.10512,{"date":325,"score":319,"percentile":326},"2026-02-17",0.10475,{"date":328,"score":319,"percentile":329},"2026-02-18",0.10777,{"date":331,"score":319,"percentile":332},"2026-02-19",0.10857,{"date":334,"score":319,"percentile":335},"2026-02-20",0.10844,{"date":337,"score":319,"percentile":338},"2026-02-21",0.10886,{"date":340,"score":319,"percentile":341},"2026-02-22",0.10882,{"date":343,"score":319,"percentile":344},"2026-02-23",0.10835,{"date":346,"score":319,"percentile":347},"2026-02-24",0.10756,{"date":349,"score":319,"percentile":350},"2026-02-25",0.10684,{"date":352,"score":319,"percentile":353},"2026-02-26",0.1065,{"date":355,"score":319,"percentile":356},"2026-02-27",0.1067,{"date":358,"score":319,"percentile":359},"2026-02-28",0.10666,{"date":361,"score":319,"percentile":362},"2026-03-01",0.10679,{"date":364,"score":319,"percentile":365},"2026-03-02",0.1062,{"date":367,"score":319,"percentile":368},"2026-03-03",0.106,{"date":370,"score":319,"percentile":371},"2026-03-04",0.10571,{"date":373,"score":319,"percentile":374},"2026-03-05",0.10607,{"date":376,"score":319,"percentile":374},"2026-03-06",{"date":378,"score":319,"percentile":379},"2026-03-07",0.10613,{"date":381,"score":319,"percentile":382},"2026-03-08",0.10583,[],[385],{"ecosystem":9,"name":386,"vendor":387,"product":387,"cpe_part":388,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":389},"Linux","linux","a",[390,397,400,403,406,409,412,415,418],{"version":391,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":395,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C 0f0ab8d52ee0062b28367dea23c29e254a26d7db",true,"f855691975bb06373a98711e4cfe2c224244b536","including","0f0ab8d52ee0062b28367dea23c29e254a26d7db","excluding",{"version":398,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":399,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C fa6c6c04f6c9b21b315023f487e5a07ae7fcf647","fa6c6c04f6c9b21b315023f487e5a07ae7fcf647",{"version":401,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":402,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C eb47e612e59c358c3968a92f90dd36c78c9a2106","eb47e612e59c358c3968a92f90dd36c78c9a2106",{"version":404,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":405,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C ec23b25e5687dbd644c0f57bcb6af22dd5a6dd36","ec23b25e5687dbd644c0f57bcb6af22dd5a6dd36",{"version":407,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":408,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C a1639a82ce14af76b6419778d343ccbff86ee626","a1639a82ce14af76b6419778d343ccbff86ee626",{"version":410,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":411,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C 55ad2309205cc00c585344374c7472420e1b2c12","55ad2309205cc00c585344374c7472420e1b2c12",{"version":413,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":414,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C c070688bfbe7759e61e697e421b2a331b0dd74bc","c070688bfbe7759e61e697e421b2a331b0dd74bc",{"version":416,"is_range":392,"range_type":76,"version_start":393,"version_start_type":394,"version_end":417,"version_end_type":396,"fixed_in":9},">= f855691975bb06373a98711e4cfe2c224244b536, \u003C 9fd41f1ba638938c9a1195d09bc6fa3be2712f25","9fd41f1ba638938c9a1195d09bc6fa3be2712f25",{"version":419,"is_range":69,"range_type":76,"version_start":419,"version_start_type":394,"version_end":419,"version_end_type":394,"fixed_in":9},"3.19"]