🛡️ UBUNTU-CVE-2023-52854
⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

In the Linux kernel, the following vulnerability has been resolved: padata: Fix refcnt handling in padata_free_shell() In a high-load arm64 environment, the pcrypt_aead01 test in LTP can lead to system UAF (Use-After-Free) issues. Due to the lengthy analysis of the pcrypt_aead01 function call, I'll describe the problem scenario using a simplified model: Suppose there's a user of padata named `user_function` that adheres to the padata requirement of calling `padata_free_shell` after `serial()` has been invoked, as demonstrated in the following code: ```c struct request { struct padata_priv padata; struct completion *done; }; void parallel(struct padata_priv *padata) { do_something(); } void serial(struct padata_priv *padata) { struct request *request = container_of(padata, struct request, padata); complete(request->done); } void user_function() { DECLARE_COMPLETION(done) padata->parallel = parallel; padata->serial = serial; padata_do_parallel(); wait_for_completion(&done); padata_free_shell(); } ``` In the corresponding padata.c file, there's the following code: ```c static void padata_serial_worker(struct work_struct *serial_work) { ... cnt = 0; while (!list_empty(&local_list)) { ... padata->serial(padata); cnt++; } local_bh_enable(); if (refcount_sub_and_test(cnt, &pd->refcnt)) padata_free_pd(pd); } ``` Because of the high system load and the accumulation of unexecuted softirq at this moment, `local_bh_enable()` in padata takes longer to execute than usual. Subsequently, when accessing `pd->refcnt`, `pd` has already been released by `padata_free_shell()`, resulting in a UAF issue with `pd->refcnt`. The fix is straightforward: add `refcount_dec_and_test` before calling `padata_free_pd` in `padata_free_shell`.

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-05-21
Updated 2026-06-15
Modified 2026-06-04
Fix URL N/A

Affected Packages

Software From version Fixed in
linux 5.15.0-100.110
linux-allwinner-5.19
linux-aws 5.15.0-1056.61
linux-aws-5.0
linux-aws-5.11
linux-aws-5.13
linux-aws-5.15 5.15.0-1056.61~20.04.1
linux-aws-5.19
linux-aws-5.3
linux-aws-5.4 5.4.0-1152.162~18.04.1
linux-aws-5.8
linux-aws-6.2
linux-aws-6.5
linux-aws-fips 5.15.0-1056.61+fips1
linux-aws-hwe
linux-azure 5.15.0-1058.66
linux-azure-4.15
linux-azure-5.11
linux-azure-5.13
linux-azure-5.15 5.15.0-1058.66~20.04.2
linux-azure-5.19
linux-azure-5.3
linux-azure-5.4 5.4.0-1156.163~18.04.1
linux-azure-5.8
linux-azure-6.2
linux-azure-6.5
linux-azure-edge
linux-azure-fde
linux-azure-fde-5.19
linux-azure-fde-6.2
linux-azure-fde-6.8
linux-azure-fips
linux-bluefield
linux-fips 5.15.0-100.110+fips1
linux-gcp 5.15.0-1053.61
linux-gcp-4.15
linux-gcp-5.11
linux-gcp-5.13
linux-gcp-5.15 5.15.0-1053.61~20.04.1
linux-gcp-5.19
linux-gcp-5.3
linux-gcp-5.4 5.4.0-1155.164~18.04.1
linux-gcp-5.8
linux-gcp-6.2
linux-gcp-6.5
linux-gcp-fips 5.15.0-1055.63+fips2
linux-gke 5.15.0-1052.57
linux-gke-4.15
linux-gke-5.15
linux-gke-5.4
linux-gkeop 5.15.0-1038.44
linux-gkeop-5.15 5.15.0-1038.44~20.04.1
linux-gkeop-5.4
linux-hwe
linux-hwe-5.11
linux-hwe-5.13
linux-hwe-5.15 5.15.0-100.110~20.04.1
linux-hwe-5.19
linux-hwe-5.4 5.4.0-223.243~18.04.1
linux-hwe-5.8
linux-hwe-6.2
linux-hwe-6.5
linux-hwe-edge
linux-ibm 5.15.0-1048.51
linux-ibm-5.15 5.15.0-1048.51~20.04.1
linux-ibm-5.4 5.4.0-1098.103~18.04.1
linux-intel-5.13
linux-intel-iot-realtime 5.15.0-1048.50
linux-intel-iotg 5.15.0-1050.56
linux-intel-iotg-5.15 5.15.0-1050.56~20.04.1
linux-iot 5.4.0-1056.59
linux-kvm 5.15.0-1052.57
linux-lowlatency 5.15.0-100.110
linux-lowlatency-hwe-5.15 5.15.0-100.110~20.04.1
linux-lowlatency-hwe-5.19
linux-lowlatency-hwe-6.2
linux-lowlatency-hwe-6.5
linux-lts-xenial
linux-nvidia 5.15.0-1046.46
linux-nvidia-6.2
linux-nvidia-6.5 6.5.0-1014.14
linux-nvidia-tegra 5.15.0-1025.25
linux-nvidia-tegra-5.15 5.15.0-1025.25~20.04.1
linux-nvidia-tegra-igx 5.15.0-1012.12
linux-oem
linux-oem-5.10
linux-oem-5.13
linux-oem-5.14
linux-oem-5.17
linux-oem-5.6
linux-oem-6.0
linux-oem-6.1
linux-oem-6.5
linux-oracle 5.15.0-1053.59
linux-oracle-5.0
linux-oracle-5.11
linux-oracle-5.13
linux-oracle-5.15 5.15.0-1053.59~20.04.1
linux-oracle-5.3
linux-oracle-5.4 5.4.0-1150.160~18.04.1
linux-oracle-5.8
linux-oracle-6.5
linux-raspi 5.15.0-1048.51
linux-raspi-5.4 5.4.0-1135.148~18.04.1
linux-raspi-realtime
linux-raspi2
linux-realtime 5.15.0-1056.63
linux-riscv
linux-riscv-5.11
linux-riscv-5.15 5.15.0-1051.55~20.04.1
linux-riscv-5.19
linux-riscv-5.8
linux-riscv-6.5
linux-starfive-5.19
linux-starfive-6.2
linux-starfive-6.5
linux-xilinx-zynqmp 5.15.0-1030.34

References

Similar Threats

Site Security Check

Concerned your site may already be targeted?

BotEraser analyzes incoming traffic patterns and helps identify bot behavior consistent with known exploit attempts.

Check My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.