CVE-2023-53535
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53535 is a vulnerability in the Linux kernel's bcmgenet network driver, discovered and disclosed on October 4, 2025. The vulnerability affects the packet handling mechanism where oversized packets from hardware could exceed the nominal 2KiB buffer size allocated for SKBs (Socket Buffers) (NVD CVE Details).

Technical details

The vulnerability exists in the bcmgenet network driver's packet handling mechanism. When hardware sends packets that exceed the nominal 2KiB buffer size allocated for Socket Buffers (SKBs), it could trigger an skboverpanic() condition. According to Red Hat's assessment, this vulnerability has been assigned a CVSS v3.1 score of 7.0 with the vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H (Red Hat Security).

Impact

The vulnerability could lead to system instability when processing oversized network packets in the bcmgenet driver. If exploited, it could cause the system to panic when handling packets that exceed the allocated buffer size, potentially resulting in system crashes or denial of service conditions (NVD CVE Details).

Mitigation and workarounds

A fix has been implemented that adds an early check to drop oversized packets before they can trigger the skboverpanic() condition, allowing the system to continue processing subsequent packets normally. The patch has been integrated into the Linux kernel (NVD CVE Details).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management