CVE-2023-2593
published 2025-07-30CVE-2023-2593: A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.73%
50.6th percentile
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.7-1 (bookworm) | linux 6.1.7-1 (bookworm) |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-595c-mc93-mp4p: A flaw exists within the Linux kernel's handling of new TCP connections
ghsa_unreviewed·2025-07-30
CVE-2023-2593 [MEDIUM] CWE-835 GHSA-595c-mc93-mp4p: A flaw exists within the Linux kernel's handling of new TCP connections
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.
OSV
CVE-2023-2593: A flaw exists within the Linux kernel's handling of new TCP connections
osv·2025-07-30·CVSS 5.9
CVE-2023-2593 [MEDIUM] CVE-2023-2593: A flaw exists within the Linux kernel's handling of new TCP connections
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.
Red Hat
kernel: ksmbd Memory Exhaustion Denial-of-Service Vulnerability
vendor_redhat·2023-05-17·CVSS 5.9
CVE-2023-2593 [MEDIUM] CWE-835 kernel: ksmbd Memory Exhaustion Denial-of-Service Vulnerability
kernel: ksmbd Memory Exhaustion Denial-of-Service Vulnerability
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.
Statement: The ksmbd kernel component is not shipped with any Red Hat Products.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Packa
Debian
CVE-2023-2593: linux - A flaw exists within the Linux kernel's handling of new TCP connections. The iss...
vendor_debian·2023·CVSS 5.9
CVE-2023-2593 [MEDIUM] CVE-2023-2593: linux - A flaw exists within the Linux kernel's handling of new TCP connections. The iss...
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved
forky: resolved (fixed in 6.1.7-1)
sid: resolved (fixed in 6.1.7-1)
trixie: resolved (fixed in 6.1.7-1)
No detection rules found.
No public exploits indexed.
2025-07-30
Published