CVE-2023-2006: Linux Kernel

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel.

Affected products

  • Linux Linux Kernel: from 5.10, before 5.10.157 (fixed in 5.10.157); from 5.11, before 5.15.81 (fixed in 5.15.81); from 5.16, before 6.0.11 (fixed in 6.0.11)
  • Netapp Hci Baseboard Management Controller: version h300s only; version h410c only; version h410s only; version h500s only; version h700s only

Published 2023-04-24. Last modified 2026-06-17.