---
id: CVE-2023-2593
title: A flaw exists within the Linux kernel's handling of new TCP connections
summary: >-
  A flaw exists within the Linux kernel's handling of new TCP connections. The
  issue results from the lack of memory release after its effective lifetime.
  This vulnerability allows an unauthenticated attacker to create a denial of
  service …
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-835
published: '2025-07-30'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-2593'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2023-2593'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2384787'
    label: secalert@redhat.com
  - url: >-
      https://lore.kernel.org/lkml/CAH2r5msyEy20e=FBx6wPWWc3kXzNR4b+zHshSqidRdFKVf_7Jg@mail.gmail.com/
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00732
epssPercentile: 0.52925
ingestedAt: '2026-06-29T13:24:34.401Z'
---

## Overview

A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
