PT-2025-54047 · Linux+1 · Linux Kernel+1

CVE-2023-54218

·

Published

2023-05-09

·

Updated

2026-07-03

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.3.0-rc7-02330-gca6270c12e20
Description The Linux kernel contained a data race condition in the sock recv cmsgs() function, specifically related to accessing sk->sk stamp. Kernel Concurrency Sanitizer (KCSAN) identified that a read access to sk->sk stamp required READ ONCE() to prevent load-tearing. The issue was observed during packet recvmsg and sock recvmsg operations. The vulnerability was reported by KCSAN and addressed in a recent kernel build. The functions involved include sock write timestamp, sock recv cmsgs, packet recvmsg, sock recvmsg nosec, sock read iter, call read iter, vfs read, ksys read, do sys read, se sys read, and x64 sys read.
Recommendations Update to a version of the Linux kernel newer than 6.3.0-rc7-02330-gca6270c12e20.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13769
CVE-2023-54218
OESA-2026-1276
SUSE-SU-2026:0473-1

Affected Products

Linux Kernel
Red Os