---
id: CVE-2023-35788
title: >-
  An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the
  Linux kernel before 6.3.7
summary: >-
  An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the
  Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower
  classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in
  denial…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: adp
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-04-23T13:29:16.172490Z'
exploitAvailable: true
published: '2023-06-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:02:02.809Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-35788'
references:
  - url: 'https://www.openwall.com/lists/oss-security/2023/06/07/1'
  - url: 'https://git.kernel.org/linus/4d56304e5827c8cc8cc18c75343d283af7c4825c'
  - url: 'https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.7'
  - url: 'http://www.openwall.com/lists/oss-security/2023/06/17/1'
    label: '[oss-security] 20230617 Re: Linux kernel: off-by-one in fl_set_geneve_opt'
  - url: 'https://www.debian.org/security/2023/dsa-5448'
    label: DSA-5448
  - url: 'https://security.netapp.com/advisory/ntap-20230714-0002/'
  - url: 'https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html'
    label: >-
      [debian-lts-announce] 20230727 [SECURITY] [DLA 3508-1] linux security
      update
  - url: 'https://www.debian.org/security/2023/dsa-5480'
    label: DSA-5480
  - url: >-
      http://packetstormsecurity.com/files/174577/Kernel-Live-Patch-Security-Notice-LSN-0097-1.html
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html'
    label: >-
      [debian-lts-announce] 20231019 [SECURITY] [DLA 3623-1] linux-5.10 security
      update
tags:
  - cve.org
  - exploit-available
epss: 0.00532
epssPercentile: 0.42541
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/lanleft/cve-2023-35788'
  checkedAt: '2026-09-26T09:05:29.881Z'
ingestedAt: '2026-09-18T15:44:31.589Z'
---

## Overview

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
