cbcvebase.
CVE-2023-53809
published 2025-12-09

CVE-2023-53809: In the Linux kernel, the following vulnerability has been resolved: l2tp: Avoid possible recursive deadlock in l2tp_tunnel_register() When a file descriptor of…

PriorityP420low5.5
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: l2tp: Avoid possible recursive deadlock in l2tp_tunnel_register() When a file descriptor of pppol2tp socket is passed as file descriptor of UDP socket, a recursive deadlock occurs in l2tp_tunnel_register(). This situation is reproduced by the following program: int main(void) { int sock; struct sockaddr_pppol2tp addr; sock = socket(AF_PPPOX, SOCK_DGRAM, PX_PROTO_OL2TP); if (sock dump_stack_lvl+0x100/0x178 __lock_acquire.cold+0x119/0x3b9 ? lockdep_hardirqs_on_prepare+0x410/0x410 lock_acquire+0x1e0/0x610 ? l2tp_tunnel_register+0x2b7/0x11c0 ? lock_downgrade+0x710/0x710 ? __fget_files+0x283/0x3e0 lock_sock_nested+0x3a/0xf0 ? l2tp_tunnel_register+0x2b7/0x11c0 l2tp_tunnel_register+0x2b7/0x11c0 ? sprintf+0xc4/0x100 ? l2tp_tunnel_del_work+0x6b0/0x6b0 ? debug_object_deactivate+0x320/0x320 ? lockdep_init_map_type+0x16d/0x7a0 ? lockdep_init_map_type+0x16d/0x7a0 ? l2tp_tunnel_create+0x2bf/0x4b0 ? l2tp_tunnel_create+0x3c6/0x4b0 pppol2tp_connect+0x14e1/0x1a30 ? pppol2tp_put_sk+0xd0/0xd0 ? aa_sk_perm+0x2b7/0xa80 ? aa_af_perm+0x260/0x260 ? bpf_lsm_socket_connect+0x9/0x10 ? pppol2tp_put_sk+0xd0/0xd0 __sys_connect_file+0x14f/0x190 __sys_connect+0x133/0x160 ? __sys_connect_file+0x190/0x190 ? lockdep_hardirqs_on+0x7d/0x100 ? ktime_get_coarse_real_ts64+0x1b7/0x200 ? ktime_get_coarse_real_ts64+0x147/0x200 ? __audit_syscall_entry+0x396/0x500 __x64_sys_connect+0x72/0xb0 do_syscall_64+0x38/0xb0 entry_SYSCALL_64_after_hwframe+0x63/0xcd This patch fixes the issue by getting/creating the tunnel before locking the pppol2tp socket.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 0b2c59720e65885a394a017d0cf9cab118914682 < 5370647dd745bb3d8f37057006be207ddd8e93145370647dd745bb3d8f37057006be207ddd8e9314
linuxlinux>= 0b2c59720e65885a394a017d0cf9cab118914682 < 9ca5e7ecab064f1f47da07f7c1ddf40e4bc0e5ac9ca5e7ecab064f1f47da07f7c1ddf40e4bc0e5ac
linuxlinux>= 2d77e5c0ad79004b5ef901895437e9cce6dfcc7e < 4a413d360959962995e16a899cf2b9ef53e9fcb94a413d360959962995e16a899cf2b9ef53e9fcb9
linuxlinux>= 5.10.166 < 5.10.1735.10.173
linuxlinux>= 5.15.91 < 5.15.995.15.99
linuxlinux>= 6.1.9 < 6.1.166.1.16
linuxlinux>= 77e8ed776cdb1a24b2aab8fe7c6f1f154235e1ce < f6df58aa15f7d469f69b1dd21b001ff483255244f6df58aa15f7d469f69b1dd21b001ff483255244
linuxlinux>= cef0845b6dcfa2f6c2c832e7f9622551456c741d < 4bb736b40475528ac1aa8c98b368563618488a704bb736b40475528ac1aa8c98b368563618488a70
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 5.10.1735.10.173
linuxlinux_kernel>= 5.11.0 < 5.15.995.15.99
linuxlinux_kernel>= 5.16.0 < 6.1.166.1.16
linuxlinux_kernel>= 6.2.0 < 6.2.36.2.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.