CVE Database
/

CVE-2023-53731

Back to search

CVE-2023-53731

Published: Oct 22, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: netlink: fix potential deadlock in netlink_set_err() syzbot reported a possible deadlock in netlink_set_err() [1] A similar issue was fixed in commit 1d482e666b8e ("netlink: disable IRQs for netlink_lock_table()") in netlink_lock_table() This patch adds IRQ safety to netlink_set_err() and __netlink_diag_dump() which were not covered by cited commit. [1] WARNING: possible irq lock inversion dependency detected 6.4.0-rc6-syzkaller-00240-g4e9f0ec38852 #0 Not tainted syz-executor.2/23011 just changed the state of lock: ffffffff8e1a7a58 (nl_table_lock){.+.?}-{2:2}, at: netlink_set_err+0x2e/0x3a0 net/netlink/af_netlink.c:1612 but this lock was taken by another, SOFTIRQ-safe lock in the past: (&local->queue_stop_reason_lock){..-.}-{2:2} and interrupts could create inverse lock ordering between them. other info that might help us debug this: Possible interrupt unsafe locking scenario: CPU0 CPU1 ---- ---- lock(nl_table_lock); local_irq_disable(); lock(&local->queue_stop_reason_lock); lock(nl_table_lock); <Interrupt> lock(&local->queue_stop_reason_lock); *** DEADLOCK ***

VendorProductVersions

Linux

Linux

affected
82b2ea5f904b3826934df4a00f3b8806272185f6 - < c09e8e3f7fd432984bf5422302b093d2371dfc48
affected
59fba11d649854134c75ad88c8adafa9304ac419 - < 4b9adb8d4a62ff7608d4a7d4eb42036a88f30980
affected
21df0c2e7d195de4a3c650de9361b3037fa6c59a - < 8f6652ed2ad98fe6d13b903483d9257762ab2ec6
affected
1d6d43d4805da9b3fa0f5841e8b1083c89868f35 - < cde7b90e0539a3b11da377e463dfd2288a162dbf
affected
1d482e666b8e74c7555dbdfbfb77205eeed3ff2d - < a641240b7e071c5538dc0e7894ece833fce459dd

+14 more versions

Linux

Linux

affected
5.13
unaffected
0 - < 5.13
unaffected
4.14.322 - <= 4.14.*
unaffected
4.19.291 - <= 4.19.*
unaffected
5.4.251 - <= 5.4.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now