SB20250916292 - Infinite loop in Linux kernel openvswitch
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Infinite loop (CVE-ID: CVE-2023-53188)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the do_output() function in net/openvswitch/actions.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/066b86787fa3d97b7aefb5ac0a99a22dad2d15f8
- https://git.kernel.org/stable/c/284be5db6c8d06d247ed056cfc448c4f79bbb16c
- https://git.kernel.org/stable/c/56252da41426f3d01957456f13caf46ce670ea29
- https://git.kernel.org/stable/c/5efcb301523baacd98a47553d4996e924923114d
- https://git.kernel.org/stable/c/644b3051b06ba465bc7401bfae9b14963cbc8c1c
- https://git.kernel.org/stable/c/9b0dd09c1ceb35950d2884848099fccc9ec9a123
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.293