CVE-2023-53839: Linux
EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: dccp: fix data-race around dp->dccps_mss_cache dccp_sendmsg() reads dp->dccps_mss_cache before locking the socket. Same thing in do_dccp_getsockopt(). Add READ_ONCE()/WRITE_ONCE() annotations, and change dccp_sendmsg() to check again dccps_mss_cache after socket is locked.
Affected products
- Linux Linux: from 2.6.14, before 4.14.323 (fixed in 4.14.323); from 4.15, before 4.19.292 (fixed in 4.19.292); from 4.20, before 5.4.254 (fixed in 5.4.254); from 5.5, before 5.10.191 (fixed in 5.10.191); from 5.11, before 5.15.127 (fixed in 5.15.127); from 5.16, before 6.1.46 (fixed in 6.1.46); …
Published 2025-12-09. Last modified 2026-06-17.