SB20251230251 - Improper locking in Linux kernel tls
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2023-54306)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the tls_sw_sendmsg(), tls_sw_sendpage() and tx_work_handler() functions in net/tls/tls_sw.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f800f6aae57d2d8f63d32fff383017cbc11cf65
- https://git.kernel.org/stable/c/7123a4337bf73132bbfb5437e4dc83ba864a9a1e
- https://git.kernel.org/stable/c/bde541a57b4204d0a800afbbd3d1c06c9cdb133f
- https://git.kernel.org/stable/c/be5d5d0637fd88c18ee76024bdb22649a1de00d6
- https://git.kernel.org/stable/c/ccf1ccdc5926907befbe880b562b2a4b5f44c087
- https://git.kernel.org/stable/c/f3221361dc85d4de22586ce8441ec2c67b454f5d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.173
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.100
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.235
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.18
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3