Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Affecting torvalds/linux package, versions [,6.6-rc3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-TORVALDSLINUX-5924444
  • published28 Sept 2023
  • disclosed28 Sept 2023
  • creditUnknown

Introduced: 28 Sep 2023

CVE-2023-42756  (opens in a new tab)
CWE-362  (opens in a new tab)

How to fix?

Upgrade torvalds/linux to version 6.6-rc3 or higher.

Overview

Affected versions of this package are vulnerable to Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') due to the Netfilter subsystem of the Linux kernel. An attacker can cause a kernel panic and crash the system by exploiting a race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP which leads to the invocation of __ip_set_put on a wrong set.

CVSS Scores

version 3.1