PT-2025-49715 · Linux+1 · Linux Kernel+1

CVE-2023-53824

·

Published

2025-12-09

·

Updated

2026-07-01

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.3.0-rc4-syzkaller-00195-g5a57b48fdfcb
Description The Linux kernel contained a data-race condition within the netlink recvmsg() function. This issue was identified through reports from syzbot, indicating concurrent access to nlk->max recvmsg len without proper locking mechanisms. The data-race occurred during concurrent execution of netlink recvmsg() and netlink dump(), potentially leading to unpredictable behavior or system instability. The issue involves read and write operations to memory location 0xffff888141840b38 by different tasks on separate CPUs.
Recommendations Update the Linux kernel to version 6.3.0-rc4-syzkaller-00195-g5a57b48fdfcb or a later version that includes the fix for this data-race condition.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-53824

Affected Products

Linux Kernel
Red Os