CVE-2023-53590: sctp: add a refcnt in sctp_stream_priorities to avoid a nested loop
In the Linux kernel, the following vulnerability has been resolved:
sctp: add a refcnt in sctpstreampriorities to avoid a nested loop
With this refcnt added in sctpstreampriorities, we don't need to traverse all streams to check if the prio is used by other streams when freeing one stream's prio in sctpschedpriofreesid(). This can avoid a nested loop (up to 65535 65535), which may cause a stuck as Ying reported:
watchdog: BUG: soft lockup - CPU#23 stuck for 26s! [ksoftirqd/23:136] Call Trace: <TASK> sctpschedpriofreesid+0xab/0x100 [sctp] sctpstreamfreeext+0x64/0xa0 [sctp] sctpstreamfree+0x31/0x50 [sctp] sctpassociationfree+0xa5/0x200 [sctp]
Note that it doesn't need to use refcountt type for this counter, as its accessing is always protected under the sock lock.
v1->v2: - add a check in sctpschedprioset to avoid the possible priohead refcnt overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53590?
CVE-2023-53590 has a medium severity level due to its impact on the Linux kernel functionality.
How do I fix CVE-2023-53590?
To fix CVE-2023-53590, you should upgrade to the latest version of the Linux kernel where this vulnerability has been addressed.
What systems are affected by CVE-2023-53590?
CVE-2023-53590 affects various versions of the Linux kernel utilized by multiple Linux distributions.
What type of vulnerability is CVE-2023-53590?
CVE-2023-53590 is a vulnerability in the Linux kernel related to SCTP stream priorities.
Is CVE-2023-53590 being actively exploited?
As of now, there are no reported active exploits for CVE-2023-53590.