PT-2025-54170 · Linux+1 · Linux Kernel+1

Published

2023-01-01

·

Updated

2026-04-20

·

CVE-2023-54324

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the multipath target when the retrieve deps function runs concurrently with multipath message. This occurs because retrieve deps iterates through a list of open devices without holding a lock, while multipath message can add or remove devices from the list simultaneously. This can lead to memory corruption or a use-after-free condition. The issue involves calls to the dm get device and dm put device functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2023-54324
RHSA-2024:2394
RHSA-2024:3138
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1

Affected Products

Debian
Linux Kernel