🛡️ UBUNTU-CVE-2023-52527
⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

In the Linux kernel, the following vulnerability has been resolved: ipv4, ipv6: Fix handling of transhdrlen in __ip{,6}_append_data() Including the transhdrlen in length is a problem when the packet is partially filled (e.g. something like send(MSG_MORE) happened previously) when appending to an IPv4 or IPv6 packet as we don't want to repeat the transport header or account for it twice. This can happen under some circumstances, such as splicing into an L2TP socket. The symptom observed is a warning in __ip6_append_data(): WARNING: CPU: 1 PID: 5042 at net/ipv6/ip6_output.c:1800 __ip6_append_data.isra.0+0x1be8/0x47f0 net/ipv6/ip6_output.c:1800 that occurs when MSG_SPLICE_PAGES is used to append more data to an already partially occupied skbuff. The warning occurs when 'copy' is larger than the amount of data in the message iterator. This is because the requested length includes the transport header length when it shouldn't. This can be triggered by, for example: sfd = socket(AF_INET6, SOCK_DGRAM, IPPROTO_L2TP); bind(sfd, ...); // ::1 connect(sfd, ...); // ::1 port 7 send(sfd, buffer, 4100, MSG_MORE); sendfile(sfd, dfd, NULL, 1024); Fix this by only adding transhdrlen into the length if the write queue is empty in l2tp_ip6_sendmsg(), analogously to how UDP does things. l2tp_ip_sendmsg() looks like it won't suffer from this problem as it builds the UDP packet itself.

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-03-02
Updated 2026-06-15
Modified 2026-06-04
Fix URL N/A

Affected Packages

Software From version Fixed in
linux 5.15.0-94.104
linux-allwinner-5.19
linux-aws 5.15.0-1053.58
linux-aws-5.0
linux-aws-5.11
linux-aws-5.13
linux-aws-5.15 5.15.0-1053.58~20.04.1
linux-aws-5.19
linux-aws-5.3
linux-aws-5.4 5.4.0-1118.128~18.04.1
linux-aws-5.8
linux-aws-6.2
linux-aws-6.5
linux-aws-fips 5.15.0-1053.58+fips1
linux-aws-hwe 4.15.0-1173.186~16.04.1
linux-azure 5.15.0-1056.64
linux-azure-4.15 4.15.0-1181.196
linux-azure-5.11
linux-azure-5.13
linux-azure-5.15 5.15.0-1056.64~20.04.1
linux-azure-5.19
linux-azure-5.3
linux-azure-5.4 5.4.0-1123.130~18.04.1
linux-azure-5.8
linux-azure-6.2
linux-azure-6.5
linux-azure-edge
linux-azure-fde
linux-azure-fde-5.19
linux-azure-fde-6.2
linux-azure-fde-6.8
linux-azure-fips
linux-bluefield
linux-fips 5.15.0-94.104+fips1
linux-gcp 5.15.0-1051.59
linux-gcp-4.15 4.15.0-1166.183
linux-gcp-5.11
linux-gcp-5.13
linux-gcp-5.15 5.15.0-1051.59~20.04.1
linux-gcp-5.19
linux-gcp-5.3
linux-gcp-5.4 5.4.0-1122.131~18.04.1
linux-gcp-5.8
linux-gcp-6.2
linux-gcp-6.5
linux-gcp-fips 5.15.0-1055.63+fips2
linux-gke 5.15.0-1050.55
linux-gke-4.15
linux-gke-5.15
linux-gke-5.4
linux-gkeop 5.15.0-1036.42
linux-gkeop-5.15 5.15.0-1036.42~20.04.1
linux-gkeop-5.4
linux-hwe
linux-hwe-5.11
linux-hwe-5.13
linux-hwe-5.15 5.15.0-94.104~20.04.1
linux-hwe-5.19
linux-hwe-5.4 5.4.0-171.189~18.04.1
linux-hwe-5.8
linux-hwe-6.2
linux-hwe-6.5
linux-hwe-edge
linux-ibm 5.15.0-1046.49
linux-ibm-5.15 5.15.0-1046.49~20.04.1
linux-ibm-5.4 5.4.0-1065.70~18.04.1
linux-intel-5.13
linux-intel-iot-realtime 5.15.0-1046.48
linux-intel-iotg 5.15.0-1047.53
linux-intel-iotg-5.15 5.15.0-1048.54~20.04.1
linux-iot 5.4.0-1030.31
linux-kvm 5.15.0-1050.55
linux-lowlatency 5.15.0-94.104
linux-lowlatency-hwe-5.15 5.15.0-94.104~20.04.1
linux-lowlatency-hwe-5.19
linux-lowlatency-hwe-6.2
linux-lowlatency-hwe-6.5
linux-lts-xenial 4.4.0-259.293~14.04.1
linux-nvidia 5.15.0-1044.44
linux-nvidia-6.2
linux-nvidia-6.5 6.5.0-1014.14
linux-nvidia-tegra 5.15.0-1022.22
linux-nvidia-tegra-5.15 5.15.0-1022.22~20.04.1
linux-nvidia-tegra-igx 5.15.0-1009.9
linux-oem
linux-oem-5.10
linux-oem-5.13
linux-oem-5.14
linux-oem-5.17
linux-oem-5.6
linux-oem-6.0
linux-oem-6.1
linux-oem-6.5
linux-oracle 5.15.0-1051.57
linux-oracle-5.0
linux-oracle-5.11
linux-oracle-5.13
linux-oracle-5.15 5.15.0-1051.57~20.04.1
linux-oracle-5.3
linux-oracle-5.4 5.4.0-1117.126~18.04.1
linux-oracle-5.8
linux-oracle-6.5
linux-raspi 5.15.0-1046.49
linux-raspi-5.4 5.4.0-1102.114~18.04.1
linux-raspi-realtime
linux-raspi2
linux-realtime 5.15.0-1054.60
linux-riscv
linux-riscv-5.11
linux-riscv-5.15 5.15.0-1049.53~20.04.2
linux-riscv-5.19
linux-riscv-5.8
linux-starfive-5.19
linux-starfive-6.2
linux-xilinx-zynqmp 5.15.0-1027.31

Similar Threats

Site Security Check

Concerned your site may already be targeted?

BotEraser analyzes incoming traffic patterns and helps identify bot behavior consistent with known exploit attempts.

Check My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.