CVE-2023-53439: net: skb_partial_csum_set() fix against transport header magic value

Published Sep 18, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: skbpartialcsumset() fix against transport header magic value

skb->transportheader uses the special 0xFFFF value to mark if the transport header was set or not.

We must prevent callers to accidentaly set skb->transportheader to 0xFFFF. Note that only fuzzers can possibly do this today.

syzbot reported:

WARNING: CPU: 0 PID: 2340 at include/linux/skbuff.h:2847 skbtransportoffset include/linux/skbuff.h:2956 [inline] WARNING: CPU: 0 PID: 2340 at include/linux/skbuff.h:2847 virtionethdrtoskb+0xbcc/0x10c0 include/linux/virtionet.h:103 Modules linked in: CPU: 0 PID: 2340 Comm: syz-executor.0 Not tainted 6.3.0-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/14/2023 RIP: 0010:skbtransportheader include/linux/skbuff.h:2847 [inline] RIP: 0010:skbtransportoffset include/linux/skbuff.h:2956 [inline] RIP: 0010:virtionethdrtoskb+0xbcc/0x10c0 include/linux/virtionet.h:103 Code: 41 39 df 0f 82 c3 04 00 00 48 8b 7c 24 10 44 89 e6 e8 08 6e 59 ff 48 85 c0 74 54 e8 ce 36 7e fc e9 37 f8 ff ff e8 c4 36 7e fc <0f> 0b e9 93 f8 ff ff 44 89 f7 44 89 e6 e8 32 38 7e fc 45 39 e6 0f RSP: 0018:ffffc90004497880 EFLAGS: 00010293 RAX: ffffffff84fea55c RBX: 000000000000ffff RCX: ffff888120be2100 RDX: 0000000000000000 RSI: 000000000000ffff RDI: 000000000000ffff RBP: ffffc90004497990 R08: ffffffff84fe9de5 R09: 0000000000000034 R10: ffffea00048ebd80 R11: 0000000000000034 R12: ffff88811dc2d9c8 R13: dffffc0000000000 R14: ffff88811dc2d9ae R15: 1ffff11023b85b35 FS: 00007f9211a59700(0000) GS:ffff8881f6c00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00000000200002c0 CR3: 00000001215a5000 CR4: 00000000003506f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> packetsnd net/packet/afpacket.c:3076 [inline] packetsendmsg+0x4590/0x61a0 net/packet/afpacket.c:3115 socksendmsgnosec net/socket.c:724 [inline] socksendmsg net/socket.c:747 [inline] syssendto+0x472/0x630 net/socket.c:2144 dosyssendto net/socket.c:2156 [inline] sesyssendto net/socket.c:2152 [inline] x64syssendto+0xe5/0x100 net/socket.c:2152 dosyscallx64 arch/x86/entry/common.c:50 [inline] dosyscall64+0x2f/0x50 arch/x86/entry/common.c:80 entrySYSCALL64afterhwframe+0x63/0xcd RIP: 0033:0x7f9210c8c169 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 f1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f9211a59168 EFLAGS: 00000246 ORIGRAX: 000000000000002c RAX: ffffffffffffffda RBX: 00007f9210dabf80 RCX: 00007f9210c8c169 RDX: 000000000000ffed RSI: 00000000200000c0 RDI: 0000000000000003 RBP: 00007f9210ce7ca1 R08: 0000000020000540 R09: 0000000000000014 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007ffe135d65cf R14: 00007f9211a59300 R15: 0000000000022000

Affected Software

4 affected components
Linux Kernel
Linux Linux kernel>=5.19<6.1.30
Linux Linux kernel>=6.2<6.3.4
Linux Linux kernel=6.4-rc1

Event History

Sep 18, 2025
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-53439?

CVE-2023-53439 has a medium severity rating due to potential issues with transport header processing in the Linux kernel.

2

How do I fix CVE-2023-53439?

To fix CVE-2023-53439, update your Linux kernel to the latest patched version that addresses this vulnerability.

3

What software is affected by CVE-2023-53439?

CVE-2023-53439 affects the Linux kernel, specifically versions prior to the release that contained the fix.

4

What types of attacks can CVE-2023-53439 allow?

CVE-2023-53439 could potentially allow for Denial of Service (DoS) attacks or other unexpected behavior in network communication.

5

Is CVE-2023-53439 actively exploited?

As of now, there are no known active exploits reported for CVE-2023-53439, but updating is recommended to mitigate any risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203