SB2025091876 - Improper locking in Linux kernel ipv6
Published: September 18, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2023-53365)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ip6mr_cache_report() function in net/ipv6/ip6mr.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0438e60a00d4e335b3c36397dbf26c74b5d13ef0
- https://git.kernel.org/stable/c/1683124129a4263dd5bce2475bab110e95fa0346
- https://git.kernel.org/stable/c/1bb54a21f4d9b88442f8c3307c780e2db64417e4
- https://git.kernel.org/stable/c/30e0191b16e8a58e4620fa3e2839ddc7b9d4281c
- https://git.kernel.org/stable/c/3326c711f18d18fe6e1f5d83d3a7eab07e5a1560
- https://git.kernel.org/stable/c/691a09eecad97e745b9aa0e3918db46d020bdacb
- https://git.kernel.org/stable/c/8382e7ed2d63e6c2daf6881fa091526dc6c879cd
- https://git.kernel.org/stable/c/a96d74d1076c82a4cef02c150d9996b21354c78d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.322