Critical· 9.1official fix available
CVE-2023-53600
A vulnerability in the Linux kernel's tunneling component causes a memory error when generating specific network error messages. This error occurs when the system tries to process certain types of network packets.
publishedOct 4, 2025
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
19th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 3, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Users running Linux kernel version 6.5 or specific release candidates.
02
Real-world impact
An attacker could potentially cause a system crash or service disruption, making the affected machine unresponsive.
03
Why this severity
The critical score is due to the vulnerability being remotely exploitable over a network without requiring user interaction or special privileges, potentially leading to a complete loss of availability.
04
What to do about it
official fix available
recommended steps
- 01Update the Linux kernel to a version that includes the fix for the tunnels component.
NVD-referenced vendor advisory
05
Timeline
- Oct 4, 2025 · Oct 4, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactNone
Availability impactHigh
07
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →