cbcvebase.
CVE-2023-53731
published 2025-10-22

CVE-2023-53731: In the Linux kernel, the following vulnerability has been resolved: netlink: fix potential deadlock in netlink_set_err() syzbot reported a possible deadlock in…

PriorityP421low5.5
EPSS
0.22%
12.1th percentile
In the Linux kernel, the following vulnerability has been resolved: netlink: fix potential deadlock in netlink_set_err() syzbot reported a possible deadlock in netlink_set_err() [1] A similar issue was fixed in commit 1d482e666b8e ("netlink: disable IRQs for netlink_lock_table()") in netlink_lock_table() This patch adds IRQ safety to netlink_set_err() and __netlink_diag_dump() which were not covered by cited commit. [1] WARNING: possible irq lock inversion dependency detected 6.4.0-rc6-syzkaller-00240-g4e9f0ec38852 #0 Not tainted syz-executor.2/23011 just changed the state of lock: ffffffff8e1a7a58 (nl_table_lock){.+.?}-{2:2}, at: netlink_set_err+0x2e/0x3a0 net/netlink/af_netlink.c:1612 but this lock was taken by another, SOFTIRQ-safe lock in the past: (&local->queue_stop_reason_lock){..-.}-{2:2} and interrupts could create inverse lock ordering between them. other info that might help us debug this: Possible interrupt unsafe locking scenario: CPU0 CPU1 ---- ---- lock(nl_table_lock); local_irq_disable(); lock(&local->queue_stop_reason_lock); lock(nl_table_lock); lock(&local->queue_stop_reason_lock); *** DEADLOCK ***

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 1d482e666b8e74c7555dbdfbfb77205eeed3ff2d < a641240b7e071c5538dc0e7894ece833fce459dda641240b7e071c5538dc0e7894ece833fce459dd
linuxlinux>= 1d482e666b8e74c7555dbdfbfb77205eeed3ff2d < 61ffe8b1ee084e5c82a4e4bbf9e7b68e0c06e46461ffe8b1ee084e5c82a4e4bbf9e7b68e0c06e464
linuxlinux>= 1d482e666b8e74c7555dbdfbfb77205eeed3ff2d < eb8e27c8fa9397b4a7b181c48fa58157dbe9902eeb8e27c8fa9397b4a7b181c48fa58157dbe9902e
linuxlinux>= 1d482e666b8e74c7555dbdfbfb77205eeed3ff2d < 1556ba034b95cfd4f75ea93c1a2679ae0444bba11556ba034b95cfd4f75ea93c1a2679ae0444bba1
linuxlinux>= 1d482e666b8e74c7555dbdfbfb77205eeed3ff2d < 8d61f926d42045961e6b65191c09e3678d86a9cf8d61f926d42045961e6b65191c09e3678d86a9cf
linuxlinux>= 1d6d43d4805da9b3fa0f5841e8b1083c89868f35 < cde7b90e0539a3b11da377e463dfd2288a162dbfcde7b90e0539a3b11da377e463dfd2288a162dbf
linuxlinux>= 21df0c2e7d195de4a3c650de9361b3037fa6c59a < 8f6652ed2ad98fe6d13b903483d9257762ab2ec68f6652ed2ad98fe6d13b903483d9257762ab2ec6
linuxlinux>= 4.14.237 < 4.14.3224.14.322
linuxlinux>= 4.19.195 < 4.19.2914.19.291
linuxlinux>= 4.4.273 < 4.54.5
linuxlinux>= 4.9.273 < 4.104.10
linuxlinux>= 5.10.44 < 5.10.1885.10.188
linuxlinux>= 5.12.11 < 5.135.13
linuxlinux>= 5.4.126 < 5.4.2515.4.251
linuxlinux>= 59fba11d649854134c75ad88c8adafa9304ac419 < 4b9adb8d4a62ff7608d4a7d4eb42036a88f309804b9adb8d4a62ff7608d4a7d4eb42036a88f30980
linuxlinux>= 82b2ea5f904b3826934df4a00f3b8806272185f6 < c09e8e3f7fd432984bf5422302b093d2371dfc48c09e8e3f7fd432984bf5422302b093d2371dfc48
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.