VYPR
Medium severity5.5NVD Advisory· Published Mar 27, 2025· Updated Jun 17, 2026

CVE-2023-52996

CVE-2023-52996

Description

In the Linux kernel, the following vulnerability has been resolved:

ipv4: prevent potential spectre v1 gadget in fib_metrics_match()

if (!type) continue; if (type > RTAX_MAX) return false; ... fi_val = fi->fib_metrics->metrics[type - 1];

@type being used as an array index, we need to prevent cpu speculation or risk leaking kernel memory content.

Affected products

9
  • Linux/Kernel8 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.14,<5.4.231
    • cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.2:rc5:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 4.14
  • osv-coords
    Range: >= 4.14.0, < 5.4.231

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.