LiveActive security incident?Get immediate response
CVE Record

CVE-2023-54006: af_unix: Fix data-race around unix_tot_inflight.

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix data-race around unix_tot_inflight. unix_tot_inflight is changed under spin_lock(unix_gc_lock), but unix_release_sock() reads it locklessly. Let's use READ_ONCE() for unix_tot_inflight. Note that the writer side was marked by commit 9d6d7f1cb67c ("af_unix: annote lockless accesses to unix_tot_inflight & gc_in_progress") BUG: KCSAN: data-race in unix_inflight / unix_release_sock write (marked) to 0xffffffff871852b8 of 4 bytes by task 123 on cpu 1: unix_inflight+0x130/0x180 net/unix/scm.c:64 unix_attach_fds+0x137/0x1b0 net/unix/scm.c:123 unix_scm_to_skb net/unix/af_unix.c:1832 [inline] unix_dgram_sendmsg+0x46a/0x14f0 net/unix/af_unix.c:1955 sock_sendmsg_nosec net/socket.c:724 [inline] sock_sendmsg+0x148/0x160 net/socket.c:747 ____sys_sendmsg+0x4e4/0x610 net/socket.c:2493 ___sys_sendmsg+0xc6/0x140 net/socket.c:2547 __sys_sendmsg+0x94/0x140 net/socket.c:2576 __do_sys_sendmsg net/socket.c:2585 [inline] __se_sys_sendmsg net/socket.c:2583 [inline] __x64_sys_sendmsg+0x45/0x50 net/socket.c:2583 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x72/0xdc read to 0xffffffff871852b8 of 4 bytes by task 4891 on cpu 0: unix_release_sock+0x608/0x910 net/unix/af_unix.c:671 unix_release+0x59/0x80 net/unix/af_unix.c:1058 __sock_release+0x7d/0x170 net/socket.c:653 sock_close+0x19/0x30 net/socket.c:1385 __fput+0x179/0x5e0 fs/file_table.c:321 ____fput+0x15/0x20 fs/file_table.c:349 task_work_run+0x116/0x1a0 kernel/task_work.c:179 resume_user_mode_work include/linux/resume_user_mode.h:49 [inline] exit_to_user_mode_loop kernel/entry/common.c:171 [inline] exit_to_user_mode_prepare+0x174/0x180 kernel/entry/common.c:204 __syscall_exit_to_user_mode_work kernel/entry/common.c:286 [inline] syscall_exit_to_user_mode+0x1a/0x30 kernel/entry/common.c:297 do_syscall_64+0x4b/0x90 arch/x86/entry/common.c:86 entry_SYSCALL_64_after_hwframe+0x72/0xdc value changed: 0x00000000 -> 0x00000001 Reported by Kernel Concurrency Sanitizer on: CPU: 0 PID: 4891 Comm: systemd-coredum Not tainted 6.4.0-rc5-01219-gfa0e21fa4443 #5 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel data-race fix in Unix domain socket handling. The public record does not describe a concrete security impact such as privilege escalation, crash, or data leak. Treat it as a kernel correctness issue that should be remediated through normal kernel update channels unless your vendor rates it higher.

Executive priority

Track and remediate in the regular kernel patch cycle. Escalate only if your Linux vendor assigns material severity or links the issue to a concrete exploit path.

Technical view

unix_tot_inflight is updated under unix_gc_lock but was read locklessly in unix_release_sock. KCSAN reported a race between AF_UNIX sendmsg file-descriptor passing and socket release. The upstream fix uses READ_ONCE() for the lockless read.

Likely exposure

Exposure is limited to Linux systems running affected kernel code paths for AF_UNIX sockets. The bundle lists Linux kernel versions and stable commits but does not provide distribution package mappings, exploitability, or business-impact details.

Exploitation context

The source bundle marks KEV as false and provides no cited evidence of active exploitation or a public exploit. The evidence is a Kernel Concurrency Sanitizer race report, not a weaponized attack description.

Researcher notes

Available evidence supports a narrow concurrency bug in AF_UNIX inflight descriptor accounting. The bundle lacks CVSS, CWE, exploitability analysis, or affected distribution package data, so impact should not be overstated.

Mitigation direction

  • Update to a vendor kernel containing the referenced stable fix.
  • Check distribution advisories for CVE-2023-54006 package mappings.
  • Prioritize internet-facing hosts only if vendor guidance elevates severity.
  • Reboot systems after kernel updates to run the fixed kernel.
  • If no vendor fix is available, monitor vendor guidance.

Validation and detection

  • Inventory running Linux kernel versions across servers and containers hosts.
  • Compare installed kernels against vendor advisories for CVE-2023-54006.
  • Confirm the booted kernel changed after patching and reboot.
  • Review kernel changelogs for the referenced AF_UNIX stable commits.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-54006 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
9Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8, 9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8, 9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8, 9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8, 9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8, 9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8, 9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8, 9305cfa4443dbfb99faf35c5603ec0c0e91b5ef8unaffected
LinuxLinux2.6.24, 0, 4.14.326, 4.19.295, 5.4.257, 5.10.195, 5.15.132, 6.1.54, 6.5.4, 6.6affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.