Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53021— net/sched: sch_taprio: fix possible use-after-free

AI Predicted 7.8 Difficulty: Hard EPSS 0.18% · P8

Possible ATT&CK Techniques 1AI

T1135 · Network Share Discovery

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux5a781ccbd19e4664babcbe4b4ead7aa2b9283d22< 1200388a0b1c3c6fda48d4d2143db8f7e4ef5348affected
5a781ccbd19e4664babcbe4b4ead7aa2b9283d22< c60fe70078d6e515f424cb868d07e00411b27fbcaffected
5a781ccbd19e4664babcbe4b4ead7aa2b9283d22< c53acbf2facfdfabdc6e6984a1a38f5d38b606a1affected
5a781ccbd19e4664babcbe4b4ead7aa2b9283d22< d3b2d2820a005e43855fa71b80c4a4b194201c60affected
5a781ccbd19e4664babcbe4b4ead7aa2b9283d22< 3a415d59c1dbec9d772dbfab2d2520d98360caaeaffected
4.20affected
< 4.20unaffected
5.4.231≤ 5.4.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-53021

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net/sched: sch_taprio: fix possible use-after-free
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: fix possible use-after-free syzbot reported a nasty crash [1] in net_tx_action() which made little sense until we got a repro. This repro installs a taprio qdisc, but providing an invalid TCA_RATE attribute. qdisc_create() has to destroy the just initialized taprio qdisc, and taprio_destroy() is called. However, the hrtimer used by taprio had already fired, therefore advance_sched() called __netif_schedule(). Then net_tx_action was trying to use a destroyed qdisc. We can not undo the __netif_schedule(), so we must wait until one cpu serviced the qdisc before we can proceed. Many thanks to Alexander Potapenko for his help. [1] BUG: KMSAN: uninit-value in queued_spin_trylock include/asm-generic/qspinlock.h:94 [inline] BUG: KMSAN: uninit-value in do_raw_spin_trylock include/linux/spinlock.h:191 [inline] BUG: KMSAN: uninit-value in __raw_spin_trylock include/linux/spinlock_api_smp.h:89 [inline] BUG: KMSAN: uninit-value in _raw_spin_trylock+0x92/0xa0 kernel/locking/spinlock.c:138 queued_spin_trylock include/asm-generic/qspinlock.h:94 [inline] do_raw_spin_trylock include/linux/spinlock.h:191 [inline] __raw_spin_trylock include/linux/spinlock_api_smp.h:89 [inline] _raw_spin_trylock+0x92/0xa0 kernel/locking/spinlock.c:138 spin_trylock include/linux/spinlock.h:359 [inline] qdisc_run_begin include/net/sch_generic.h:187 [inline] qdisc_run+0xee/0x540 include/net/pkt_sched.h:125 net_tx_action+0x77c/0x9a0 net/core/dev.c:5086 __do_softirq+0x1cc/0x7fb kernel/softirq.c:571 run_ksoftirqd+0x2c/0x50 kernel/softirq.c:934 smpboot_thread_fn+0x554/0x9f0 kernel/smpboot.c:164 kthread+0x31b/0x430 kernel/kthread.c:376 ret_from_fork+0x1f/0x30 Uninit was created at: slab_post_alloc_hook mm/slab.h:732 [inline] slab_alloc_node mm/slub.c:3258 [inline] __kmalloc_node_track_caller+0x814/0x1250 mm/slub.c:4970 kmalloc_reserve net/core/skbuff.c:358 [inline] __alloc_skb+0x346/0xcf0 net/core/skbuff.c:430 alloc_skb include/linux/skbuff.h:1257 [inline] nlmsg_new include/net/netlink.h:953 [inline] netlink_ack+0x5f3/0x12b0 net/netlink/af_netlink.c:2436 netlink_rcv_skb+0x55d/0x6c0 net/netlink/af_netlink.c:2507 rtnetlink_rcv+0x30/0x40 net/core/rtnetlink.c:6108 netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline] netlink_unicast+0xf3b/0x1270 net/netlink/af_netlink.c:1345 netlink_sendmsg+0x1288/0x1440 net/netlink/af_netlink.c:1921 sock_sendmsg_nosec net/socket.c:714 [inline] sock_sendmsg net/socket.c:734 [inline] ____sys_sendmsg+0xabc/0xe90 net/socket.c:2482 ___sys_sendmsg+0x2a1/0x3f0 net/socket.c:2536 __sys_sendmsg net/socket.c:2565 [inline] __do_sys_sendmsg net/socket.c:2574 [inline] __se_sys_sendmsg net/socket.c:2572 [inline] __x64_sys_sendmsg+0x367/0x540 net/socket.c:2572 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x63/0xcd CPU: 0 PID: 13 Comm: ksoftirqd/0 Not tainted 6.0.0-rc2-syzkaller-47461-gac3859c02d7f #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/22/2022
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于net_tx_action可能使用已销毁的qdisc。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 5a781ccbd19e4664babcbe4b4ead7aa2b9283d22 ~ 1200388a0b1c3c6fda48d4d2143db8f7e4ef5348 -
LinuxLinux 4.20 -

II. Public POCs for CVE-2023-53021

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53021

登录查看更多情报信息。

Patches & Fixes for CVE-2023-53021 (1)

Same Patch Batch · Linux · 2025-03-27 · 124 CVEs total

CVE-2025-218768.8 HIGHiommu/vt-d: Fix suspicious RCU usage
CVE-2025-218908.2 HIGHidpf: fix checksums set in idpf_rx_rsc()
CVE-2025-218897.8 HIGHperf/core: Add RCU read lock protection to perf_iterate_ctx()
CVE-2025-218707.8 HIGHASoC: SOF: ipc4-topology: Harden loops for looking up ALH copiers
CVE-2025-218877.8 HIGHovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up
CVE-2025-218677.8 HIGHbpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
CVE-2025-218757.8 HIGHmptcp: always handle address removal under msk socket lock
CVE-2025-218847.8 HIGHnet: better track kernel sockets lifetime
CVE-2025-218797.8 HIGHbtrfs: fix use-after-free on inode when scanning root during em shrinking
CVE-2025-218827.8 HIGHnet/mlx5: Fix vport QoS cleanup on error
CVE-2025-218687.5 HIGHnet: allow small head cache usage with large MAX_SKB_FRAGS values
CVE-2025-218857.5 HIGHRDMA/bnxt_re: Fix the page details for the srq created by kernel consumers
CVE-2023-52994acpi: Fix suspend with Xen PV
CVE-2023-52988ALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path()
CVE-2023-52989firewire: fix memory leak for payload of request subaction to IEC 61883-1 FCP region
CVE-2023-52991net: fix NULL pointer in skb_segment_list
CVE-2023-53000netlink: prevent potential spectre v1 gadgets
CVE-2023-52999net: fix UaF in netns ops registration error path
CVE-2023-52998net: fec: Use page_pool_put_full_page when freeing rx buffers
CVE-2023-52997ipv4: prevent potential spectre v1 gadget in ip_metrics_convert()

Showing top 20 of 124 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53021

No comments yet


Leave a comment