CVE-2023-53995 is a Linux kernel vulnerability in the IPv4 networking stack caused by incorrect handling in __inet_del_ifa() during deletion of an IPv4 interface address. In a specific sequence involving bonded interfaces, promote_secondaries behavior, primary and secondary IPv4 address manipulation, and subsequent interface teardown, __inet_del_ifa() can compute an incorrect last_prim value. This causes a promoted secondary address to be lost instead of being correctly repositioned, resulting in a leak of the secondary address object and leaked references to associated in_device and net_device objects. The flaw was identified through fuzzing and was fixed by changing the logic so last_prim is searched starting from the location of the deleted address and the promoted address is inserted at the correct position.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel IPv4 memory-leak vulnerability in __inet_del_ifa() addressed by the SUSE kernel live-patch update.
Linux kernel IPv4 memory-leak vulnerability in __inet_del_ifa(), addressed by the SUSE SLES12 live-patch update.
Linux IPv4 memory-leak vulnerability in __inet_del_ifa().
Linux kernel IPv4 memory-leak vulnerability in __inet_del_ifa().
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.