CVE-2023-53782 Details
Description
In the Linux kernel, the following vulnerability has been resolved: dccp: Fix out of bounds access in DCCP error handler There was a previous attempt to fix an out-of-bounds access in the DCCP error handlers, but that fix assumed that the error handlers only want to access the first 8 bytes of the DCCP header. Actually, they also look at the DCCP sequence number, which is stored beyond 8 bytes, so an explicit pskb_may_pull() is required.
A vulnerability has been identified in the Linux kernel's Datagram Congestion Control Protocol (DCCP) error handling, specifically in versions prior to the latest patch. The issue arises from an out-of-bounds access where the error handlers incorrectly assumed they only needed to read the first 8 bytes of the DCCP header. In reality, they also require access to the DCCP sequence number, which is located beyond the initial 8 bytes. This oversight necessitates an explicit call to 'pskb_may_pull()' to ensure proper data handling.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched. Instructions for upgrading the kernel can be found in the official Linux documentation or through the package manager for your Linux distribution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/177212bf6dc1ff2d13d0409cddc5c9e81feec63d | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/3533e10272555c422a7d51ebc0ce8c483429f7f2 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/4b8a938e329ae4eb54b73b0c87b5170607b038a8 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/6ecf09699eb1554299aa1e7fd13e9e80f656c2f9 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/7a7dd70cb954d3efa706a429687ded88c02496fa | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/977ad86c2a1bcaf58f01ab98df5cc145083c489c | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/d8171411a661253e6271fa10b65b46daf1b6471c | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/ec620c34f5fa5d055f9f6136a387755db6157712 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/f8a7f10a1dccf9868ff09342a73dce27501b86df | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 9, 2025 | New CVE Received | kernel.org |
Volerion