cbcvebase.
CVE-2023-54218
published 2025-12-30

CVE-2023-54218: In the Linux kernel, the following vulnerability has been resolved: net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). KCSAN found a data race in…

PriorityP422low3.3
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net: Fix load-tearing on sk->sk_stamp in sock_recv_cmsgs(). KCSAN found a data race in sock_recv_cmsgs() where the read access to sk->sk_stamp needs READ_ONCE(). BUG: KCSAN: data-race in packet_recvmsg / packet_recvmsg write (marked) to 0xffff88803c81f258 of 8 bytes by task 19171 on cpu 0: sock_write_timestamp include/net/sock.h:2670 [inline] sock_recv_cmsgs include/net/sock.h:2722 [inline] packet_recvmsg+0xb97/0xd00 net/packet/af_packet.c:3489 sock_recvmsg_nosec net/socket.c:1019 [inline] sock_recvmsg+0x11a/0x130 net/socket.c:1040 sock_read_iter+0x176/0x220 net/socket.c:1118 call_read_iter include/linux/fs.h:1845 [inline] new_sync_read fs/read_write.c:389 [inline] vfs_read+0x5e0/0x630 fs/read_write.c:470 ksys_read+0x163/0x1a0 fs/read_write.c:613 __do_sys_read fs/read_write.c:623 [inline] __se_sys_read fs/read_write.c:621 [inline] __x64_sys_read+0x41/0x50 fs/read_write.c:621 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x72/0xdc read to 0xffff88803c81f258 of 8 bytes by task 19183 on cpu 1: sock_recv_cmsgs include/net/sock.h:2721 [inline] packet_recvmsg+0xb64/0xd00 net/packet/af_packet.c:3489 sock_recvmsg_nosec net/socket.c:1019 [inline] sock_recvmsg+0x11a/0x130 net/socket.c:1040 sock_read_iter+0x176/0x220 net/socket.c:1118 call_read_iter include/linux/fs.h:1845 [inline] new_sync_read fs/read_write.c:389 [inline] vfs_read+0x5e0/0x630 fs/read_write.c:470 ksys_read+0x163/0x1a0 fs/read_write.c:613 __do_sys_read fs/read_write.c:623 [inline] __se_sys_read fs/read_write.c:621 [inline] __x64_sys_read+0x41/0x50 fs/read_write.c:621 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x72/0xdc value changed: 0xffffffffc4653600 -> 0x0000000000000000 Reported by Kernel Concurrency Sanitizer on: CPU: 1 PID: 19183 Comm: syz-executor.5 Not ta

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < fd28692fa182d25e8d26bc1db506648839fde245fd28692fa182d25e8d26bc1db506648839fde245
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < 564c3150ad357d571a0de7d8b644aa1f7e6e21b7564c3150ad357d571a0de7d8b644aa1f7e6e21b7
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < d7343f8de019ebb55b2b6ef79b971f6ceb361a99d7343f8de019ebb55b2b6ef79b971f6ceb361a99
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < d06f67b2b8dcd00d995c468428b6bccebc5762d8d06f67b2b8dcd00d995c468428b6bccebc5762d8
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < de260d1e02cde39d317066835ee6e5234fc9f5a8de260d1e02cde39d317066835ee6e5234fc9f5a8
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < 7145f2309d649ad6273b9f66448321b9b4c523c87145f2309d649ad6273b9f66448321b9b4c523c8
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < 8319220054e5ea5f506d8d4c4b5e234f668ffc3b8319220054e5ea5f506d8d4c4b5e234f668ffc3b
linuxlinux>= 6c7c98bad4883a4a8710c96b2b44de482865eb6e < dfd9248c071a3710c24365897459538551cb7167dfd9248c071a3710c24365897459538551cb7167
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.12.0 < 4.14.3164.14.316
linuxlinux_kernel>= 4.15.0 < 4.19.2844.19.284
linuxlinux_kernel>= 4.20.0 < 5.4.2445.4.244
linuxlinux_kernel>= 5.11.0 < 5.15.1135.15.113
linuxlinux_kernel>= 5.16.0 < 6.1.306.1.30
linuxlinux_kernel>= 5.5.0 < 5.10.1815.10.181
linuxlinux_kernel>= 6.2.0 < 6.3.46.3.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.