CVE-2023-53218

HIGH EPSS 4.7%
Published Sep 15, 20259mo ago · Modified Jun 17, 20262w ago
7.8 CVSS 3.1
High
Find Similar
Published Sep 15, 2025 9mo ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Make it so that a waiting process can be aborted When sendmsg() creates an rxrpc call, it queues it to wait for a connection and channel to be assigned and then waits before it can start shovelling data as the encrypted DATA packet content includes a summary of the connection parameters. However, sendmsg() may get interrupted before a connection gets assigned and further sendmsg() calls will fail with EBUSY until an assignment is made. Fix this so that the call can at least be aborted without failing on EBUSY. We have to be careful here as sendmsg() mustn't be allowed to start the call timer if the call doesn't yet have a connection assigned as an oops may follow shortly thereafter.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
4.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 2

VendorProductVersionRange
linuxlinux_kernel*≥4.11  –  <6.2.16
linuxlinux_kernel*≥6.3  –  <6.3.3

References 3

  • git.kernel.org https://git.kernel.org/stable/c/0eb362d254814ce04848730bf32e75b8ee1a4d6c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7161cf61c64e9e9413d790f2fa2b9dada71a2249
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/876d96faacbc407daf4978d7ec95051b68f5344a
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0eb362d254814ce04848730bf32e75b8ee1a4d6c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7161cf61c64e9e9413d790f2fa2b9dada71a2249
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/876d96faacbc407daf4978d7ec95051b68f5344a
    Patch