CVE-2023-53815: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: posix-timers: Prevent RT livelock in itimer_delete() itimer_delete() has a retry loop when the timer is concurrently expired. On non-RT kernels this just spin-waits until the timer callback has completed, except for posix CPU timers which have HAVE_POSIX_CPU_TIMERS_TASK_WORK enabled. In that case and on RT kernels the existing task could live lock when preempting the task which does the timer delivery. Replace spin_unlock() with an invocation of timer_wait_running() to handle it the same way as the other retry loops in the posix timer code.
Affected products
- Linux Linux: from 5.4, before 5.10.188 (fixed in 5.10.188); from 5.11, before 5.15.121 (fixed in 5.15.121); from 5.16, before 6.1.39 (fixed in 6.1.39); from 6.2, before 6.3.13 (fixed in 6.3.13); from 6.4, before 6.4.4 (fixed in 6.4.4)
Published 2025-12-09. Last modified 2026-06-17.