CVE-2023-53218: rxrpc: Make it so that a waiting process can be aborted
In the Linux kernel, the following vulnerability has been resolved:
rxrpc: Make it so that a waiting process can be aborted
When sendmsg() creates an rxrpc call, it queues it to wait for a connection and channel to be assigned and then waits before it can start shovelling data as the encrypted DATA packet content includes a summary of the connection parameters.
However, sendmsg() may get interrupted before a connection gets assigned and further sendmsg() calls will fail with EBUSY until an assignment is made.
Fix this so that the call can at least be aborted without failing on EBUSY. We have to be careful here as sendmsg() mustn't be allowed to start the call timer if the call doesn't yet have a connection assigned as an oops may follow shortly thereafter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53218?
CVE-2023-53218 has a medium severity level as it involves a potential denial of service due to process waiting behavior.
How do I fix CVE-2023-53218?
To fix CVE-2023-53218, update your Linux kernel to the latest version that addresses this vulnerability.
What versions of the Linux kernel are affected by CVE-2023-53218?
CVE-2023-53218 affects Linux kernel versions from 4.11 up to 6.2.16 and from 6.3 to 6.3.3.
Who is impacted by CVE-2023-53218?
Users and systems running the affected versions of the Linux kernel may experience issues related to process management.
What is the nature of the vulnerability in CVE-2023-53218?
The nature of CVE-2023-53218 is that it allows a waiting process to be aborted, which can lead to disruptions in communication.