{"id":"DEBIAN-CVE-2023-54218","details":"In the Linux kernel, the following vulnerability has been resolved:  net: Fix load-tearing on sk-\u003esk_stamp in sock_recv_cmsgs().  KCSAN found a data race in sock_recv_cmsgs() where the read access to sk-\u003esk_stamp needs READ_ONCE().  BUG: KCSAN: data-race in packet_recvmsg / packet_recvmsg  write (marked) to 0xffff88803c81f258 of 8 bytes by task 19171 on cpu 0:  sock_write_timestamp include/net/sock.h:2670 [inline]  sock_recv_cmsgs include/net/sock.h:2722 [inline]  packet_recvmsg+0xb97/0xd00 net/packet/af_packet.c:3489  sock_recvmsg_nosec net/socket.c:1019 [inline]  sock_recvmsg+0x11a/0x130 net/socket.c:1040  sock_read_iter+0x176/0x220 net/socket.c:1118  call_read_iter include/linux/fs.h:1845 [inline]  new_sync_read fs/read_write.c:389 [inline]  vfs_read+0x5e0/0x630 fs/read_write.c:470  ksys_read+0x163/0x1a0 fs/read_write.c:613  __do_sys_read fs/read_write.c:623 [inline]  __se_sys_read fs/read_write.c:621 [inline]  __x64_sys_read+0x41/0x50 fs/read_write.c:621  do_syscall_x64 arch/x86/entry/common.c:50 [inline]  do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80  entry_SYSCALL_64_after_hwframe+0x72/0xdc  read to 0xffff88803c81f258 of 8 bytes by task 19183 on cpu 1:  sock_recv_cmsgs include/net/sock.h:2721 [inline]  packet_recvmsg+0xb64/0xd00 net/packet/af_packet.c:3489  sock_recvmsg_nosec net/socket.c:1019 [inline]  sock_recvmsg+0x11a/0x130 net/socket.c:1040  sock_read_iter+0x176/0x220 net/socket.c:1118  call_read_iter include/linux/fs.h:1845 [inline]  new_sync_read fs/read_write.c:389 [inline]  vfs_read+0x5e0/0x630 fs/read_write.c:470  ksys_read+0x163/0x1a0 fs/read_write.c:613  __do_sys_read fs/read_write.c:623 [inline]  __se_sys_read fs/read_write.c:621 [inline]  __x64_sys_read+0x41/0x50 fs/read_write.c:621  do_syscall_x64 arch/x86/entry/common.c:50 [inline]  do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80  entry_SYSCALL_64_after_hwframe+0x72/0xdc  value changed: 0xffffffffc4653600 -\u003e 0x0000000000000000  Reported by Kernel Concurrency Sanitizer on: CPU: 1 PID: 19183 Comm: syz-executor.5 Not tainted 6.3.0-rc7-02330-gca6270c12e20 #2 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014","modified":"2026-09-15T08:47:51.842048917Z","published":"2025-12-30T13:16:10.067Z","upstream":["CVE-2023-54218"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54218"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.37-1"}]}],"versions":["6.1.27-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54218.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54218.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54218.json"}}],"schema_version":"1.9.0"}