PT-2025-37646 · Linux+4 · Linux Kernel+4

Published

2024-04-30

·

Updated

2026-04-14

·

CVE-2023-53204

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A data-race condition exists in the Linux kernel related to the user->unix inflight variable within the AF UNIX socket family. The user->unix inflight variable is modified under a spin lock (unix gc lock), but is read locklessly by the too many unix fds() function. This can lead to inconsistencies and potential issues when handling a large number of UNIX domain sockets. The issue was identified through Kernel Concurrency Sanitizer (KCSAN) reporting. The functions involved include unix attach fds, unix scm to skb, unix dgram sendmsg, unix seqpacket sendmsg, sock sendmsg nosec, sock sendmsg, sys sendmsg, sys sendmsg, sys sendmsg, do sys sendmsg, se sys sendmsg, and x64 sys sendmsg.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-05871
CVE-2023-53204
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4189-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Red Os
Suse