CVE-2023-54046 (GCVE-0-2023-54046)
Vulnerability from cvelistv5
Published
2025-12-24 12:22
Modified
2026-08-05 09:16
Summary
In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Handle EBUSY correctly As it is essiv only handles the special return value of EINPROGERSS, which means that in all other cases it will free data related to the request. However, as the caller of essiv may specify MAY_BACKLOG, we also need to expect EBUSY and treat it in the same way. Otherwise backlogged requests will trigger a use-after-free.
Impacted products
Vendor Product Version
Linux Linux Version: be1eb7f78aa8fbe34779c56c266ccd0364604e71
Version: be1eb7f78aa8fbe34779c56c266ccd0364604e71
Version: be1eb7f78aa8fbe34779c56c266ccd0364604e71
Version: be1eb7f78aa8fbe34779c56c266ccd0364604e71
Version: be1eb7f78aa8fbe34779c56c266ccd0364604e71
Version: be1eb7f78aa8fbe34779c56c266ccd0364604e71
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "crypto/essiv.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "c61e7d182ee3f3f5ecf18a2964e303d49c539b52",
              "status": "affected",
              "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
              "versionType": "git"
            },
            {
              "lessThan": "796e02cca30a67322161f0745e5ce994bbe75605",
              "status": "affected",
              "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
              "versionType": "git"
            },
            {
              "lessThan": "840a1d3b77c1b062bd62b4733969a5b1efc274ce",
              "status": "affected",
              "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
              "versionType": "git"
            },
            {
              "lessThan": "a006aa3eedb8bfd6fe317c3cfe9c86ffe76b2385",
              "status": "affected",
              "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
              "versionType": "git"
            },
            {
              "lessThan": "69c67d451fc19d88e54f7d97e8e7c093e08357e1",
              "status": "affected",
              "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
              "versionType": "git"
            },
            {
              "lessThan": "b5a772adf45a32c68bef28e60621f12617161556",
              "status": "affected",
              "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "crypto/essiv.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.4"
            },
            {
              "lessThan": "5.4",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.235",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.173",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.99",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.16",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.2.*",
              "status": "unaffected",
              "version": "6.2.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.3",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.235",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.173",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.99",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.16",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.2.3",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.3",
                  "versionStartIncluding": "5.4",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: essiv - Handle EBUSY correctly\n\nAs it is essiv only handles the special return value of EINPROGERSS,\nwhich means that in all other cases it will free data related to the\nrequest.\n\nHowever, as the caller of essiv may specify MAY_BACKLOG, we also need\nto expect EBUSY and treat it in the same way.  Otherwise backlogged\nrequests will trigger a use-after-free."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The essiv AEAD transform is driven only by local paths \u2014 dm-crypt block I/O on a locally-mapped encrypted volume, or an AF_ALG socket \u2014 with no remote peer parsing attacker data. No network-facing consumer of essiv(aead) exists.\nAC:L - Once a system runs dm-crypt with AEAD+ESSIV over a backlog-queueing crypto accelerator, an attacker can saturate that queue at will with sustained concurrent I/O, so the -EBUSY window is attacker-created rather than incidental.\nPR:L - No capability is required \u2014 an unprivileged local user with access to a file on the encrypted volume (or an AF_ALG aead socket) generates the crypto requests that reach essiv_aead_crypt(); dm-crypt setup is pre-existing administrative configuration, not a privilege the attacker must hold.\nUI:N - The vulnerable path is exercised by the attacker\u0027s own I/O or socket operations; no victim action is needed beyond the encrypted device already being mapped.\nS:U - The freed buffer and the resulting heap corruption are entirely within the kernel\u0027s own memory and security authority, with no crossing into a hypervisor, IOMMU, or other domain.\nC:H - The prematurely freed buffer is still consumed as AAD by the queued request, so reallocated heap contents are read and folded into the authentication tag returned to the caller, and the double-free yields a UAF primitive usable for arbitrary kernel reads.\nI:H - Freeing the same slab pointer two or three times lets an attacker free an object that has since been reallocated, producing overlapping-object type confusion \u2014 a well-established route to arbitrary kernel write and control-flow hijack.\nA:H - Use-after-free plus double-free corrupts the SLUB freelist and trips KASAN/BUG_ON, causing kernel oops or panic even when not exploited further."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T09:16:45.094Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/c61e7d182ee3f3f5ecf18a2964e303d49c539b52"
        },
        {
          "url": "https://git.kernel.org/stable/c/796e02cca30a67322161f0745e5ce994bbe75605"
        },
        {
          "url": "https://git.kernel.org/stable/c/840a1d3b77c1b062bd62b4733969a5b1efc274ce"
        },
        {
          "url": "https://git.kernel.org/stable/c/a006aa3eedb8bfd6fe317c3cfe9c86ffe76b2385"
        },
        {
          "url": "https://git.kernel.org/stable/c/69c67d451fc19d88e54f7d97e8e7c093e08357e1"
        },
        {
          "url": "https://git.kernel.org/stable/c/b5a772adf45a32c68bef28e60621f12617161556"
        }
      ],
      "title": "crypto: essiv - Handle EBUSY correctly",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2023-54046",
    "datePublished": "2025-12-24T12:22:57.416Z",
    "dateReserved": "2025-12-24T12:21:05.089Z",
    "dateUpdated": "2026-08-05T09:16:45.094Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…