目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-53590— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 中等 EPSS 0.11% · P2

可能的 ATT&CK 技术 1AI

T1496 · Resource Hijacking

影响版本矩阵 19

厂商产品版本范围状态
LinuxLinuxa7555681e50bdebed2c40ff7404ee73c2e932993< cec326443f01283ef68ea00c06ea073b1835a562affected
176ee6c673ccd118e9392fd2dbb165423bdb99ca< 8ee401f89cdb10f39098c0656d695b2bc4052100affected
0dfb9a566327182387c90100ea54d8426cee8c67< bf5540cbd20e2dae2c81ab9b31deef41ef147d0aaffected
9ed7bfc79542119ac0a9e1ce8a2a5285e43433e9< 03c3a5584a0a29821e59b7834635ce823050caaaaffected
9ed7bfc79542119ac0a9e1ce8a2a5285e43433e9< 6d529928ea212127851a2df8c40d822237ca946baffected
9ed7bfc79542119ac0a9e1ce8a2a5285e43433e9< 68ba44639537de6f91fe32783766322d41848127affected
fa20f88271259d42ebe66f0a8c4c20199e888c99affected
5.4.226< 5.4.235affected
… +11 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-53590 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
sctp: add a refcnt in sctp_stream_priorities to avoid a nested loop
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: sctp: add a refcnt in sctp_stream_priorities to avoid a nested loop With this refcnt added in sctp_stream_priorities, we don't need to traverse all streams to check if the prio is used by other streams when freeing one stream's prio in sctp_sched_prio_free_sid(). This can avoid a nested loop (up to 65535 * 65535), which may cause a stuck as Ying reported: watchdog: BUG: soft lockup - CPU#23 stuck for 26s! [ksoftirqd/23:136] Call Trace: <TASK> sctp_sched_prio_free_sid+0xab/0x100 [sctp] sctp_stream_free_ext+0x64/0xa0 [sctp] sctp_stream_free+0x31/0x50 [sctp] sctp_association_free+0xa5/0x200 [sctp] Note that it doesn't need to use refcount_t type for this counter, as its accessing is always protected under the sock lock. v1->v2: - add a check in sctp_sched_prio_set to avoid the possible prio_head refcnt overflow.
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于sctp_stream_priorities缺少引用计数,可能导致嵌套循环和软锁定。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux a7555681e50bdebed2c40ff7404ee73c2e932993 ~ cec326443f01283ef68ea00c06ea073b1835a562 -
LinuxLinux 6.1 -

二、漏洞 CVE-2023-53590 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-53590 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-10-04 · 共 144 条

CVE-2025-399469.8 CRITICALLinux kernel 安全漏洞
CVE-2022-50489Linux kernel 安全漏洞
CVE-2023-53580Linux kernel 安全漏洞
CVE-2022-50507Linux kernel 安全漏洞
CVE-2022-50508Linux kernel 安全漏洞
CVE-2022-50506Linux kernel 安全漏洞
CVE-2022-50504Linux kernel 安全漏洞
CVE-2022-50505Linux kernel 安全漏洞
CVE-2022-50503Linux kernel 安全漏洞
CVE-2022-50501Linux kernel 安全漏洞
CVE-2022-50500Linux kernel 安全漏洞
CVE-2022-50499Linux kernel 安全漏洞
CVE-2022-50497Linux kernel 安全漏洞
CVE-2022-50498Linux kernel 安全漏洞
CVE-2022-50496Linux kernel 安全漏洞
CVE-2022-50494Linux kernel 安全漏洞
CVE-2022-50493Linux kernel 安全漏洞
CVE-2022-50492Linux kernel 安全漏洞
CVE-2022-50490Linux kernel 安全漏洞
CVE-2023-53570Linux kernel 安全漏洞

显示前 20 条,共 144 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53590

暂无评论


发表评论