CVE-2023-53535
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53535 is a vulnerability in the Linux kernel's bcmgenet network driver, discovered and disclosed on October 4, 2025. The vulnerability affects the packet handling mechanism where oversized packets from hardware could exceed the nominal 2KiB buffer size allocated for SKBs (Socket Buffers) (NVD CVE Details).

Technical details

The vulnerability exists in the bcmgenet network driver's packet handling mechanism. When hardware sends packets that exceed the nominal 2KiB buffer size allocated for Socket Buffers (SKBs), it could trigger an skb_over_panic() condition. According to Red Hat's assessment, this vulnerability has been assigned a CVSS v3.1 score of 7.0 with the vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (Red Hat Security).

Impact

The vulnerability could lead to system instability when processing oversized network packets in the bcmgenet driver. If exploited, it could cause the system to panic when handling packets that exceed the allocated buffer size, potentially resulting in system crashes or denial of service conditions (NVD CVE Details).

Exploitability

The vulnerability requires local access and high complexity to exploit, with low privileges required and no user interaction needed, as indicated by the CVSS vector. The vulnerability has been confirmed to affect Red Hat Enterprise Linux 9 and its kernel-rt component (Red Hat Security).

Mitigation and workarounds

A fix has been implemented that adds an early check to drop oversized packets before they can trigger the skb_over_panic() condition, allowing the system to continue processing subsequent packets normally. The patch has been integrated into the Linux kernel (NVD CVE Details).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68454HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-hwe-7.0
NoYesAug 13, 2026
CVE-2026-68452HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-raspi-5.4
NoYesAug 13, 2026
CVE-2026-68451HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-nvidia
NoYesAug 13, 2026
CVE-2026-68453HIGH7.1
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-core
NoYesAug 13, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-aws
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management