SB20251230287 - Race condition within a thread in Linux kernel bpf
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition within a thread (CVE-ID: CVE-2023-54283)
The vulnerability allows a local user to corrupt data.
The vulnerability exists due to a data race within the kernel/bpf/bpf_lru_list.h. A local user can corrupt data.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6e5e83b56f50fbd1c8f7dca7df7d72c67be25571
- https://git.kernel.org/stable/c/6eaef1b1d8720053eb1b6e7a3ff8b2ff0716bb90
- https://git.kernel.org/stable/c/819ca25444b377935faa2dbb0aa3547519b5c80f
- https://git.kernel.org/stable/c/a89d14410ea0352420f03cddc67e0002dcc8f9a5
- https://git.kernel.org/stable/c/b6d9a4062c944ad095b34dc112bf646a84156f60
- https://git.kernel.org/stable/c/c006fe361cfd947f51a56793deddf891e5cbfef8
- https://git.kernel.org/stable/c/e09a285ea1e859d4cc6cb689d8d5d7c1f7c7c0d5
- https://git.kernel.org/stable/c/ee9fd0ac3017c4313be91a220a9ac4c99dde7ad4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.322
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.291
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.188
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.150
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.251
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5