PT-2025-37646 · Linux+4 · Linux Kernel+4
Published
2024-04-30
·
Updated
2026-04-14
·
CVE-2023-53204
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A data-race condition exists in the Linux kernel related to the
user->unix inflight variable within the AF UNIX socket family. The user->unix inflight variable is modified under a spin lock (unix gc lock), but is read locklessly by the too many unix fds() function. This can lead to inconsistencies and potential issues when handling a large number of UNIX domain sockets. The issue was identified through Kernel Concurrency Sanitizer (KCSAN) reporting. The functions involved include unix attach fds, unix scm to skb, unix dgram sendmsg, unix seqpacket sendmsg, sock sendmsg nosec, sock sendmsg, sys sendmsg, sys sendmsg, sys sendmsg, do sys sendmsg, se sys sendmsg, and x64 sys sendmsg.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat
Red Os
Suse