CVE-2023-54195 — Race Condition within a Thread in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Description
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix timeout of a call that hasn't yet been granted a channel
afs_make_call() calls rxrpc_kernel_begin_call() to begin a call (which may
get stalled in the background waiting for a connection to become
available); it then calls rxrpc_kernel_set_max_life() to set the timeouts -
but that starts the call timer so the call timer might then expire before
we get a connection assigned - leading to the following oops if the call…
Affected Packages3 packages
▶CVEListV5linux/linux9d35d880e0e4a3ab32d8c12f9e4d76198aadd42d — 92128a7170a220b5126d09a1c1954a3a8d46cef3+3
🔴Vulnerability Details
3OSV▶
CVE-2023-54195: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix timeout of a call that hasn't yet been granted a channel afs_make_call(↗2025-12-30
GHSA▶
GHSA-vmxf-qh3m-3qqj: In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Fix timeout of a call that hasn't yet been granted a channel
afs_make_cal↗2025-12-30