PT-2025-53999 · Linux · Linux Kernel

Published

2023-07-17

·

Updated

2026-03-24

·

CVE-2023-54170

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.3.18-150300.59.90-default #1 SLE15-SP3
Description A flaw exists in the Linux kernel related to key management. Specifically, the issue involves linking a duplicate key to a keyring’s assoc array during DNS queries. This can occur when multiple tasks concurrently make DNS queries for the same hostname, potentially leading to a duplicate index key being created in the keyring’s assoc array. This condition ultimately results in a kernel crash, as identified by a BUG ON() check within the assoc array implementation. The issue arises from the interaction between functions such as dns query(), request key and link(), construct alloc key(), and key link begin().
Recommendations Update the Linux kernel to version 5.3.18-150300.59.90-default #1 SLE15-SP3 or a later version that includes the fix.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-03602
CVE-2023-54170
RHSA-2023:7749
RHSA-2024:2394
RHSA-2024:3618
SUSE-SU-2026:0263-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0316-1
SUSE-SU-2026:0317-1
SUSE-SU-2026:0350-1
SUSE-SU-2026:0369-1
SUSE-SU-2026:0411-1
SUSE-SU-2026:0617-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1

Affected Products

Linux Kernel