CVE-2023-54306: Linux

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: tls: avoid hanging tasks on the tx_lock syzbot sent a hung task report and Eric explains that adversarial receiver may keep RWIN at 0 for a long time, so we are not guaranteed to make forward progress. Thread which took tx_lock and went to sleep may not release tx_lock for hours. Use interruptible sleep where possible and reschedule the work if it can't take the lock. Testing: existing selftest passes

Affected products

  • Linux Linux: from 5.3.11, before 5.4 (fixed in 5.4); from 5.4, before 5.4.235 (fixed in 5.4.235); from 5.5, before 5.10.173 (fixed in 5.10.173); from 5.11, before 5.15.100 (fixed in 5.15.100); from 5.16, before 6.1.18 (fixed in 6.1.18); from 6.2, before 6.2.5 (fixed in 6.2.5)

Published 2025-12-30. Last modified 2026-08-04.