#VU115802 Improper locking in Linux kernel - CVE-2023-53365
Published: September 18, 2025 / Updated: September 22, 2025
Vulnerability identifier: #VU115802
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-53365
CWE-ID: CWE-667
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ip6mr_cache_report() function in net/ipv6/ip6mr.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/0438e60a00d4e335b3c36397dbf26c74b5d13ef0
- https://git.kernel.org/stable/c/1683124129a4263dd5bce2475bab110e95fa0346
- https://git.kernel.org/stable/c/1bb54a21f4d9b88442f8c3307c780e2db64417e4
- https://git.kernel.org/stable/c/30e0191b16e8a58e4620fa3e2839ddc7b9d4281c
- https://git.kernel.org/stable/c/3326c711f18d18fe6e1f5d83d3a7eab07e5a1560
- https://git.kernel.org/stable/c/691a09eecad97e745b9aa0e3918db46d020bdacb
- https://git.kernel.org/stable/c/8382e7ed2d63e6c2daf6881fa091526dc6c879cd
- https://git.kernel.org/stable/c/a96d74d1076c82a4cef02c150d9996b21354c78d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.322