
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was identified in the Linux kernel's Data Center Bridging (DCB) implementation, specifically in how the dcbnlbcnsetcfg function parses DCBATTRBCN attributes. The issue was introduced in commit 859ee3c43812 ("DCB: Add support for DCB BCN") and has been assigned CVE-2023-53369. The vulnerability was disclosed on September 18, 2025 (NVD).
The vulnerability stems from the dcbnlbcnsetcfg function using an incorrect policy (dcbnlpfcupnest) to parse tb[DCBATTRBCN]. While the function uses dcbnlpfcupnest attributes to parse nlattr defined in dcbnlpfcupattrs, the subsequent access code fetches each nlattr as dcbnlbcnattrs attributes. This mismatch in attribute parsing could lead to a buffer overflow condition when accessing attributes beyond DCBBCNATTRBCNA_0 (NVD).
The vulnerability could potentially allow an attacker to cause a buffer overflow in the Linux kernel's DCB implementation, which might lead to memory corruption or system instability (NVD).
The issue has been resolved by using the correct policy (dcbnlbcnnest) to parse the nested tb[DCBATTRBCN] TLV (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."