CVE-2023-53769
This vulnerability in the Linux kernel’s virt/coco/sev-guest component allows a local attacker to read and tamper with encrypted messages by using shared unencrypted memory. The flaw can lead to information leakage and integrity violations. It has been fixed in a kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, specifically the virt/coco/sev-guest component. Users running affected kernel versions on systems that use this virtualization feature are at risk.
Real-world impact
A local attacker could read sensitive data or alter encrypted messages, potentially compromising the confidentiality, integrity, and availability of the system.
Why this severity
The CVSS score of 9.3 reflects that the flaw can be exploited locally without authentication, and it can completely compromise confidentiality, integrity, and availability. The attack requires no user interaction and can be performed by any local user, making it highly dangerous.
What to do about it
- 01Install the latest kernel update that contains the fix for CVE-2023-53769.
- 02Reboot the system to load the updated kernel.
NVD description indicates the vulnerability has been resolved.
Timeline
- Dec 8, 2025 · Dec 8, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.