{"id":"DEBIAN-CVE-2023-53477","details":"In the Linux kernel, the following vulnerability has been resolved:  ipv6: Add lwtunnel encap size of all siblings in nexthop calculation  In function rt6_nlmsg_size(), the length of nexthop is calculated by multipling the nexthop length of fib6_info and the number of siblings. However if the fib6_info has no lwtunnel but the siblings have lwtunnels, the nexthop length is less than it should be, and it will trigger a warning in inet6_rt_notify() as follows:  WARNING: CPU: 0 PID: 6082 at net/ipv6/route.c:6180 inet6_rt_notify+0x120/0x130 ...... Call Trace:  \u003cTASK\u003e  fib6_add_rt2node+0x685/0xa30  fib6_add+0x96/0x1b0  ip6_route_add+0x50/0xd0  inet6_rtm_newroute+0x97/0xa0  rtnetlink_rcv_msg+0x156/0x3d0  netlink_rcv_skb+0x5a/0x110  netlink_unicast+0x246/0x350  netlink_sendmsg+0x250/0x4c0  sock_sendmsg+0x66/0x70  ___sys_sendmsg+0x7c/0xd0  __sys_sendmsg+0x5d/0xb0  do_syscall_64+0x3f/0x90  entry_SYSCALL_64_after_hwframe+0x72/0xdc  This bug can be reproduced by script:  ip -6 addr add 2002::2/64 dev ens2 ip -6 route add 100::/64 via 2002::1 dev ens2 metric 100  for i in 10 20 30 40 50 60 70; do \tip link add link ens2 name ipv_$i type ipvlan \tip -6 addr add 2002::$i/64 dev ipv_$i \tifconfig ipv_$i up done  for i in 10 20 30 40 50 60; do \tip -6 route append 100::/64 encap ip6 dst 2002::$i via 2002::1 dev ipv_$i metric 100 done  ip -6 route append 100::/64 via 2002::1 dev ipv_70 metric 100  This patch fixes it by adding nexthop_len of every siblings using rt6_nh_nlmsg_size().","modified":"2026-09-15T09:02:45.094655205Z","published":"2025-10-01T12:15:50.110Z","upstream":["CVE-2023-53477"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53477"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53477.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53477.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53477.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}