CVE-2023-28466: Debian Linux

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 4.13, up to and including 5.4.240; from 5.5, before 5.10.177 (fixed in 5.10.177); from 5.11, before 5.15.105 (fixed in 5.15.105); from 5.16, before 6.1.20 (fixed in 6.1.20); from 6.2, before 6.2.7 (fixed in 6.2.7)
  • Netapp h300s: affected versions not specified
  • Netapp h410c: affected versions not specified
  • Netapp h410s: affected versions not specified
  • Netapp h500s: affected versions not specified
  • Netapp h700s: affected versions not specified

Published 2023-03-16. Last modified 2026-06-17.