CVE-2023-52654: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.9% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with unix_stream_read_generic(). The safest fix would be to completely disallow sending io_uring files via sockets via SCM_RIGHT, so there are no possible cycles invloving registered files and thus rendering SCM accounting on the io_uring side unnecessary.

Affected products

  • Linux Linux Kernel: from 5.4.220, before 5.4.264 (fixed in 5.4.264); from 5.10.150, before 5.10.204 (fixed in 5.10.204); from 5.15.75, before 5.15.143 (fixed in 5.15.143); from 5.19.17, before 5.20 (fixed in 5.20); from 6.0.3, before 6.1.68 (fixed in 6.1.68); from 6.2, before 6.6.7 (fixed in 6.6.7); …

Published 2024-05-14. Last modified 2026-08-04.