{"id":"DEBIAN-CVE-2023-53731","details":"In the Linux kernel, the following vulnerability has been resolved:  netlink: fix potential deadlock in netlink_set_err()  syzbot reported a possible deadlock in netlink_set_err() [1]  A similar issue was fixed in commit 1d482e666b8e (\"netlink: disable IRQs for netlink_lock_table()\") in netlink_lock_table()  This patch adds IRQ safety to netlink_set_err() and __netlink_diag_dump() which were not covered by cited commit.  [1]  WARNING: possible irq lock inversion dependency detected 6.4.0-rc6-syzkaller-00240-g4e9f0ec38852 #0 Not tainted  syz-executor.2/23011 just changed the state of lock: ffffffff8e1a7a58 (nl_table_lock){.+.?}-{2:2}, at: netlink_set_err+0x2e/0x3a0 net/netlink/af_netlink.c:1612 but this lock was taken by another, SOFTIRQ-safe lock in the past:  (&local-\u003equeue_stop_reason_lock){..-.}-{2:2}  and interrupts could create inverse lock ordering between them.  other info that might help us debug this:  Possible interrupt unsafe locking scenario:         CPU0                    CPU1        ----                    ----   lock(nl_table_lock);                                local_irq_disable();                                lock(&local-\u003equeue_stop_reason_lock);                                lock(nl_table_lock);   \u003cInterrupt\u003e     lock(&local-\u003equeue_stop_reason_lock);   *** DEADLOCK ***","modified":"2026-09-15T08:47:42.815697465Z","published":"2025-10-22T14:15:48.423Z","upstream":["CVE-2023-53731"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53731"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53731.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53731.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53731.json"}}],"schema_version":"1.9.0"}