CVE-2023-52997 | Linux Kernel up to 4.19.271/5.4.230/5.10.165/5.15.90/6.1.8 Kernel Memory ip_metrics_convert array index (Nessus ID 234545 / WID-SEC-2025-0649)
A vulnerability classified as problematic was found in Linux Kernel up to 4.19.271/5.4.230/5.10.165/5.15.90/6.1.8. Affected is the function ip_metrics_convert of the component Kernel Memory Handler. Such manipulation leads to improper validation of array index.
This vulnerability is traded as CVE-2023-52997. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.