#VU124565 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in Linux kernel - CVE-2026-23302
Published: March 25, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in socket state handling when processing network operations. A local user can trigger concurrent access to socket state variables to cause a denial of service.
The issue arises from improper synchronization of sk->sk_data_ready and sk->sk_write_space pointers during concurrent access by multiple CPUs.