CVE-2023-28466: Debian Linux
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 4.13, up to and including 5.4.240; from 5.5, before 5.10.177 (fixed in 5.10.177); from 5.11, before 5.15.105 (fixed in 5.15.105); from 5.16, before 6.1.20 (fixed in 6.1.20); from 6.2, before 6.2.7 (fixed in 6.2.7)
- Netapp h300s: affected versions not specified
- Netapp h410c: affected versions not specified
- Netapp h410s: affected versions not specified
- Netapp h500s: affected versions not specified
- Netapp h700s: affected versions not specified
Published 2023-03-16. Last modified 2026-06-17.