Home

Description

In the Linux kernel, the following vulnerability has been resolved: net: tls: avoid hanging tasks on the tx_lock syzbot sent a hung task report and Eric explains that adversarial receiver may keep RWIN at 0 for a long time, so we are not guaranteed to make forward progress. Thread which took tx_lock and went to sleep may not release tx_lock for hours. Use interruptible sleep where possible and reschedule the work if it can't take the lock. Testing: existing selftest passes

PUBLISHED Reserved 2025-12-30 | Published 2025-12-30 | Updated 2025-12-30 | Assigner Linux

Product status

Default status
unaffected

79ffe6087e9145d2377385cac48d0d6a6b4225a5 (git) before bde541a57b4204d0a800afbbd3d1c06c9cdb133f
affected

79ffe6087e9145d2377385cac48d0d6a6b4225a5 (git) before 7123a4337bf73132bbfb5437e4dc83ba864a9a1e
affected

79ffe6087e9145d2377385cac48d0d6a6b4225a5 (git) before be5d5d0637fd88c18ee76024bdb22649a1de00d6
affected

79ffe6087e9145d2377385cac48d0d6a6b4225a5 (git) before 1f800f6aae57d2d8f63d32fff383017cbc11cf65
affected

79ffe6087e9145d2377385cac48d0d6a6b4225a5 (git) before ccf1ccdc5926907befbe880b562b2a4b5f44c087
affected

79ffe6087e9145d2377385cac48d0d6a6b4225a5 (git) before f3221361dc85d4de22586ce8441ec2c67b454f5d
affected

c8d6817345f4ba228d07380e571676405e112872 (git)
affected

Default status
affected

5.4
affected

Any version before 5.4
unaffected

5.4.235 (semver)
unaffected

5.10.173 (semver)
unaffected

5.15.100 (semver)
unaffected

6.1.18 (semver)
unaffected

6.2.5 (semver)
unaffected

6.3 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/bde541a57b4204d0a800afbbd3d1c06c9cdb133f

git.kernel.org/...c/7123a4337bf73132bbfb5437e4dc83ba864a9a1e

git.kernel.org/...c/be5d5d0637fd88c18ee76024bdb22649a1de00d6

git.kernel.org/...c/1f800f6aae57d2d8f63d32fff383017cbc11cf65

git.kernel.org/...c/ccf1ccdc5926907befbe880b562b2a4b5f44c087

git.kernel.org/...c/f3221361dc85d4de22586ce8441ec2c67b454f5d

cve.org (CVE-2023-54306)

nvd.nist.gov (CVE-2023-54306)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.