#VU120842 Race condition within a thread in Linux kernel - CVE-2023-54283
Published: December 30, 2025 / Updated: December 30, 2025
Vulnerability identifier: #VU120842
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-54283
CWE-ID: CWE-366
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to corrupt data.
The vulnerability exists due to a data race within the kernel/bpf/bpf_lru_list.h. A local user can corrupt data.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/6e5e83b56f50fbd1c8f7dca7df7d72c67be25571
- https://git.kernel.org/stable/c/6eaef1b1d8720053eb1b6e7a3ff8b2ff0716bb90
- https://git.kernel.org/stable/c/819ca25444b377935faa2dbb0aa3547519b5c80f
- https://git.kernel.org/stable/c/a89d14410ea0352420f03cddc67e0002dcc8f9a5
- https://git.kernel.org/stable/c/b6d9a4062c944ad095b34dc112bf646a84156f60
- https://git.kernel.org/stable/c/c006fe361cfd947f51a56793deddf891e5cbfef8
- https://git.kernel.org/stable/c/e09a285ea1e859d4cc6cb689d8d5d7c1f7c7c0d5
- https://git.kernel.org/stable/c/ee9fd0ac3017c4313be91a220a9ac4c99dde7ad4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.322
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.291
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.188
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.150
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.251
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5