LiveActive security incident?Get immediate response
CVE Record

CVE-2023-54051: net: do not allow gso_size to be set to GSO_BY_FRAGS

In the Linux kernel, the following vulnerability has been resolved: net: do not allow gso_size to be set to GSO_BY_FRAGS One missing check in virtio_net_hdr_to_skb() allowed syzbot to crash kernels again [1] Do not allow gso_size to be set to GSO_BY_FRAGS (0xffff), because this magic value is used by the kernel. [1] general protection fault, probably for non-canonical address 0xdffffc000000000e: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000070-0x0000000000000077] CPU: 0 PID: 5039 Comm: syz-executor401 Not tainted 6.5.0-rc5-next-20230809-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/26/2023 RIP: 0010:skb_segment+0x1a52/0x3ef0 net/core/skbuff.c:4500 Code: 00 00 00 e9 ab eb ff ff e8 6b 96 5d f9 48 8b 84 24 00 01 00 00 48 8d 78 70 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 08 3c 03 0f 8e ea 21 00 00 48 8b 84 24 00 01 RSP: 0018:ffffc90003d3f1c8 EFLAGS: 00010202 RAX: dffffc0000000000 RBX: 000000000001fffe RCX: 0000000000000000 RDX: 000000000000000e RSI: ffffffff882a3115 RDI: 0000000000000070 RBP: ffffc90003d3f378 R08: 0000000000000005 R09: 000000000000ffff R10: 000000000000ffff R11: 5ee4a93e456187d6 R12: 000000000001ffc6 R13: dffffc0000000000 R14: 0000000000000008 R15: 000000000000ffff FS: 00005555563f2380(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000020020000 CR3: 000000001626d000 CR4: 00000000003506f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> udp6_ufo_fragment+0x9d2/0xd50 net/ipv6/udp_offload.c:109 ipv6_gso_segment+0x5c4/0x17b0 net/ipv6/ip6_offload.c:120 skb_mac_gso_segment+0x292/0x610 net/core/gso.c:53 __skb_gso_segment+0x339/0x710 net/core/gso.c:124 skb_gso_segment include/net/gso.h:83 [inline] validate_xmit_skb+0x3a5/0xf10 net/core/dev.c:3625 __dev_queue_xmit+0x8f0/0x3d60 net/core/dev.c:4329 dev_queue_xmit include/linux/netdevice.h:3082 [inline] packet_xmit+0x257/0x380 net/packet/af_packet.c:276 packet_snd net/packet/af_packet.c:3087 [inline] packet_sendmsg+0x24c7/0x5570 net/packet/af_packet.c:3119 sock_sendmsg_nosec net/socket.c:727 [inline] sock_sendmsg+0xd9/0x180 net/socket.c:750 ____sys_sendmsg+0x6ac/0x940 net/socket.c:2496 ___sys_sendmsg+0x135/0x1d0 net/socket.c:2550 __sys_sendmsg+0x117/0x1e0 net/socket.c:2579 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x38/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd RIP: 0033:0x7ff27cdb34d9

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel networking bug that can crash affected kernels when a reserved GSO size value is accepted where it should be rejected. Business impact is primarily availability risk. The source bundle does not provide CVSS, CWE, or evidence of active exploitation.

Executive priority

Treat as a normal-priority kernel availability fix unless affected systems support untrusted workloads or high-availability services. Escalate patching where a kernel crash would materially disrupt customers, operations, or shared infrastructure.

Technical view

virtio_net_hdr_to_skb() lacked a check blocking gso_size from being set to GSO_BY_FRAGS (0xffff), a kernel-reserved magic value. syzbot demonstrated a crash path ending in skb_segment(), with networking transmit and packet socket functions in the trace. Stable kernel commits add the missing validation.

Likely exposure

Exposure is limited to Linux systems running affected kernel versions or branches listed in the CVE data, including several 4.x, 5.x, 6.1, 6.4, and 6.5 lines. The bundle does not identify specific distributions, cloud images, or appliances.

Exploitation context

The provided evidence is a syzbot kernel crash, not a confirmed real-world exploit. KEV is false, and no cited source in the bundle claims active exploitation. The observable impact in the source is kernel crash/denial of service.

Researcher notes

The record is sparse: no CVSS, CWE, or distribution-specific advisories are included. The strongest evidence is the upstream/stable fix and syzbot crash trace. Avoid assuming remote reachability or privilege impact beyond the documented crash behavior.

Mitigation direction

  • Apply Linux kernel updates containing the referenced stable fixes.
  • Prioritize internet-facing, multi-tenant, and untrusted-workload Linux systems.
  • Check distribution advisories for backported fixes before relying on version strings.
  • Reduce exposure from untrusted local workloads where kernel updates are delayed.

Validation and detection

  • Inventory Linux kernel versions across affected systems.
  • Map kernel builds to the CVE record and referenced stable commits.
  • Confirm virtio_net_hdr_to_skb() rejects GSO_BY_FRAGS as gso_size.
  • Review vendor kernel changelogs for the matching networking fix.
  • Track reboot completion after patched kernel installation.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-54051 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
9Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux3953c46c3ac7eef31a9935427371c6f54a22f1ba, 3953c46c3ac7eef31a9935427371c6f54a22f1ba, 3953c46c3ac7eef31a9935427371c6f54a22f1ba, 3953c46c3ac7eef31a9935427371c6f54a22f1ba, 3953c46c3ac7eef31a9935427371c6f54a22f1ba, 3953c46c3ac7eef31a9935427371c6f54a22f1ba, 3953c46c3ac7eef31a9935427371c6f54a22f1ba, 3953c46c3ac7eef31a9935427371c6f54a22f1baunaffected
LinuxLinux4.8, 0, 4.14.324, 4.19.293, 5.4.255, 5.10.192, 5.15.128, 6.1.47, 6.4.12, 6.5affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.