CVE-2023-53809 is a deadlock vulnerability in the Linux kernel's L2TP module. It occurs when a pppol2tp socket's file descriptor is incorrectly passed as a UDP socket's file descriptor, leading to a recursive lock acquisition in l2tp_tunnel_register(). This can cause a system crash or denial of service. The vulnerability has no assigned CVSS score, but its potential for a system-level deadlock suggests a moderate to high impact. There is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.166, < 5.10.173CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.15.91, < 5.15.99CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1.9, < 6.1.16CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.