cbcvebase.
CVE-2023-54152
published 2025-12-24

CVE-2023-54152: In the Linux kernel, the following vulnerability has been resolved: can: j1939: prevent deadlock by moving j1939_sk_errqueue() This commit addresses a deadlock…

PriorityP418low5.5
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: can: j1939: prevent deadlock by moving j1939_sk_errqueue() This commit addresses a deadlock situation that can occur in certain scenarios, such as when running data TP/ETP transfer and subscribing to the error queue while receiving a net down event. The deadlock involves locks in the following order: 3 j1939_session_list_lock -> active_session_list_lock j1939_session_activate ... j1939_sk_queue_activate_next -> sk_session_queue_lock ... j1939_xtp_rx_eoma_one 2 j1939_sk_queue_drop_all -> sk_session_queue_lock ... j1939_sk_netdev_event_netdown -> j1939_socks_lock j1939_netdev_notify 1 j1939_sk_errqueue -> j1939_socks_lock __j1939_session_cancel -> active_session_list_lock j1939_tp_rxtimer CPU0 CPU1 ---- ---- lock(&priv->active_session_list_lock); lock(&jsk->sk_session_queue_lock); lock(&priv->active_session_list_lock); lock(&priv->j1939_socks_lock); The solution implemented in this commit is to move the j1939_sk_errqueue() call out of the active_session_list_lock context, thus preventing the deadlock situation.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.25-1 (bookworm)linux 6.1.25-1 (bookworm)
linuxlinux
linuxlinux>= 5b9272e93f2efe3f6cda60cc2c26817b2ce49386 < 8a581b71cf686b4cd1a85c9c2dfc2fb88382c3b48a581b71cf686b4cd1a85c9c2dfc2fb88382c3b4
linuxlinux>= 5b9272e93f2efe3f6cda60cc2c26817b2ce49386 < ace6aa2ab5ba5869563ca689bbd912100514ae7bace6aa2ab5ba5869563ca689bbd912100514ae7b
linuxlinux>= 5b9272e93f2efe3f6cda60cc2c26817b2ce49386 < f09ce9d765de1f064ce3919f57c6beb061744784f09ce9d765de1f064ce3919f57c6beb061744784
linuxlinux>= 5b9272e93f2efe3f6cda60cc2c26817b2ce49386 < d1366b283d94ac4537a4b3a1e8668da4df7ce7e9d1366b283d94ac4537a4b3a1e8668da4df7ce7e9
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 0 < 6.1.25-16.1.25-1
linuxlinux_kernel>= 5.15.0 < 5.15.1065.15.106
linuxlinux_kernel>= 5.16.0 < 6.1.236.1.23
linuxlinux_kernel>= 6.2.0 < 6.2.106.2.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.