CVE-2023-54030
published 2025-12-24CVE-2023-54030: In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overflow multishot recv Don't allow overflowing multishot recv CQEs, it…
PriorityP420low5.5
EPSS
0.15%
4.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot recv CQEs, it might get out of
hand, hurt performance, and in the worst case scenario OOM the task.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.5.3-1 (forky) | linux 6.5.3-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= b3fdea6ecb55c3ceea866ff66486927e51a982b3 < 1e2db9837be7d24a2a74eb3f3906d0872bee8907 | 1e2db9837be7d24a2a74eb3f3906d0872bee8907 |
| linux | linux | >= b3fdea6ecb55c3ceea866ff66486927e51a982b3 < b2e74db55dd93d6db22a813c9a775b5dbf87c560 | b2e74db55dd93d6db22a813c9a775b5dbf87c560 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 6.0.0 < 6.5.3 | 6.5.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54030: In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overflow multishot recv Don't allow overflowing multishot recv
osv·2025-12-24
CVE-2023-54030 CVE-2023-54030: In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overflow multishot recv Don't allow overflowing multishot recv
In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overflow multishot recv Don't allow overflowing multishot recv CQEs, it might get out of hand, hurt performance, and in the worst case scenario OOM the task.
GHSA
GHSA-43mh-5pcq-96hp: In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot re
ghsa_unreviewed·2025-12-24
CVE-2023-54030 GHSA-43mh-5pcq-96hp: In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot re
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot recv CQEs, it might get out of
hand, hurt performance, and in the worst case scenario OOM the task.
OSV
io_uring/net: don't overflow multishot recv
osv·2025-12-24
CVE-2023-54030 io_uring/net: don't overflow multishot recv
io_uring/net: don't overflow multishot recv
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot recv CQEs, it might get out of
hand, hurt performance, and in the worst case scenario OOM the task.
Red Hat
kernel: io_uring/net: don't overflow multishot recv
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54030 [LOW] kernel: io_uring/net: don't overflow multishot recv
kernel: io_uring/net: don't overflow multishot recv
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot recv CQEs, it might get out of
hand, hurt performance, and in the worst case scenario OOM the task.
A flaw was found in the Linux kernel's io_uring subsystem. When using multishot receive operations, completion queue entries (CQEs) can overflow without proper limits. This can lead to excessive memory consumption, performance degradation, and in worst cases, an out-of-memory (OOM) condition for the affected task.
Statement: This vulnerability allows a local user to exhaust memory resources through io_uring multishot receive operations. While this can cause denial of service via OOM, the impact
Debian
CVE-2023-54030: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring/ne...
vendor_debian·2023
CVE-2023-54030 CVE-2023-54030: linux - In the Linux kernel, the following vulnerability has been resolved: io_uring/ne...
In the Linux kernel, the following vulnerability has been resolved: io_uring/net: don't overflow multishot recv Don't allow overflowing multishot recv CQEs, it might get out of hand, hurt performance, and in the worst case scenario OOM the task.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
trixie: resolved (fixed in 6.5.3-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54030 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54030 CVE-2023-54030 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54030 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot recv CQEs, it might get out of
hand, hurt performance, and in the worst case scenario OOM the task.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dtb-arm
dtb-marvell
Sources
NVD
Debian 12 No Fix Added at: Dec 26, 2025
Debian 13, 14 Has Fix Added at: Dec 26, 2025
Echo Has Fix Added at: Dec 26,
Bugzilla
CVE-2023-54030 kernel: io_uring/net: don't overflow multishot recv
bugzilla·2025-12-24
CVE-2023-54030 [LOW] CVE-2023-54030 kernel: io_uring/net: don't overflow multishot recv
CVE-2023-54030 kernel: io_uring/net: don't overflow multishot recv
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: don't overflow multishot recv
Don't allow overflowing multishot recv CQEs, it might get out of
hand, hurt performance, and in the worst case scenario OOM the task.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122436-CVE-2023-54030-e7f3@gregkh/T
2025-12-24
Published