PT-2025-40678 · Linux+1 · Linux Kernel+1

Published

2024-04-30

·

Updated

2026-02-09

·

CVE-2023-53536

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The blk crypto evict key() function in the Linux kernel could lead to a use-after-free condition in blk crypto reprogram all keys() if the key is still in use or if the keyslot evict operation fails. This occurs because blk crypto evict key() may return without unlinking the key from the keyslot management structures, while the caller proceeds to free the key regardless of the return value. The fix involves ensuring that blk crypto evict key() always unlinks the key from the keyslot management structures, even on failure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
CVE-2023-53536
RHSA-2024:2394
RHSA-2024_2394

Affected Products

Linux Kernel
Red Hat