SB2025050465 - Improper locking in Linux kernel ipv4
Published: May 4, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2023-53133)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the unix_bpf_recvmsg() function in net/unix/unix_bpf.c, within the udp_bpf_recvmsg() function in net/ipv4/udp_bpf.c, within the tcp_bpf_recvmsg_parser() and tcp_bpf_recvmsg() functions in net/ipv4/tcp_bpf.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4a476285f6d2921c3c9faa494eab83b78f78fc55
- https://git.kernel.org/stable/c/bf0579989de64d36e177c0611c685dc4a91457a7
- https://git.kernel.org/stable/c/d900f3d20cc3169ce42ec72acc850e662a4d4db2
- https://git.kernel.org/stable/c/f45cf3ae3068e70e2c7f3e24a7f8e8aa99511f03
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.20