PT-2023-9728 · Linux+5 · Linux Kernel+5

Eric Dumazet

·

Published

2023-01-24

·

Updated

2025-09-29

·

CVE-2023-52735

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the sock map {close,destroy,unhash} functions in the Linux kernel, which can cause a stack overflow due to infinite recursion. This can potentially allow a remote attacker to impact the confidentiality and availability of protected information. The sock map proto callbacks should never call themselves by design, and the fix is to break out of the recursive loop to avoid a stack overflow in favor of a resource leak.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Uncontrolled Recursion

Buffer Overflow

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2024-10368
CVE-2023-52735
OESA-2024-1693
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
OPENSUSE-SU-2024_2947-1
RHSA-2023:6583
RHSA-2023_6583
RHSA-2024:5672
RHSA-2024:5673
SUSE-SU-2024:2372-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:2973-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1

Affected Products

Astra Linux
Debian
Linux Kernel
Red Hat
Red Os
Suse