CVE-2023-53821

Updated on 09 Dec 2025

Severity

7.0 High severity

Details

CVSS score
7.0

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

ip6_vti: fix slab-use-after-free in decode_session6

When ipv6_vti device is set to the qdisc of the sfb type, the cb field of the sent skb may be modified during enqueuing. Then, slab-use-after-free may occur when ipv6_vti device sends IPv6 packets.

The stack information is as follows: BUG: KASAN: slab-use-after-free in decode_session6+0x103f/0x1890 Read of size 1 at addr ffff88802e08edc2 by task swapper/0/0 CPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.4.0-next-20230707-00001-g84e2cad7f979 #410 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-1.fc33 04/01/2014 Call Trace: dump_stack_lvl+0xd9/0x150 print_address_description.constprop.0+0x2c/0x3c0 kasan_report+0x11d/0x130 decode_session6+0x103f/0x1890 __xfrm_decode_session+0x54/0xb0 vti6_tnl_xmit+0x3e6/0x1ee0 dev_hard_start_xmit+0x187/0x700 sch_direct_xmit+0x1a3/0xc30 __qdisc_run+0x510/0x17a0 __dev_queue_xmit+0x2215/0x3b10 neigh_connected_output+0x3c2/0x550 ip6_finish_output2+0x55a/0x1550 ip6_finish_output+0x6b9/0x1270 ip6_output+0x1f1/0x540 ndisc_send_skb+0xa63/0x1890 ndisc_send_rs+0x132/0x6f0 addrconf_rs_timer+0x3f1/0x870 call_timer_fn+0x1a0/0x580 expire_timers+0x29b/0x4b0 run_timer_softirq+0x326/0x910 __do_softirq+0x1d4/0x905 irq_exit_rcu+0xb7/0x120 sysvec_apic_timer_interrupt+0x97/0xc0 Allocated by task 9176: kasan_save_stack+0x22/0x40 kasan_set_track+0x25/0x30 __kasan_slab_alloc+0x7f/0x90 kmem_cache_alloc_node+0x1cd/0x410 kmalloc_reserve+0x165/0x270 __alloc_skb+0x129/0x330 netlink_sendmsg+0x9b1/0xe30 sock_sendmsg+0xde/0x190 ____sys_sendmsg+0x739/0x920 ___sys_sendmsg+0x110/0x1b0 __sys_sendmsg+0xf7/0x1c0 do_syscall_64+0x39/0xb0 entry_SYSCALL_64_after_hwframe+0x63/0xcd Freed by task 9176: kasan_save_stack+0x22/0x40 kasan_set_track+0x25/0x30 kasan_save_free_info+0x2b/0x40 ____kasan_slab_free+0x160/0x1c0 slab_free_freelist_hook+0x11b/0x220 kmem_cache_free+0xf0/0x490 skb_free_head+0x17f/0x1b0 skb_release_data+0x59c/0x850 consume_skb+0xd2/0x170 netlink_unicast+0x54f/0x7f0 netlink_sendmsg+0x926/0xe30 sock_sendmsg+0xde/0x190 ____sys_sendmsg+0x739/0x920 ___sys_sendmsg+0x110/0x1b0 __sys_sendmsg+0xf7/0x1c0 do_syscall_64+0x39/0xb0 entry_SYSCALL_64_after_hwframe+0x63/0xcd The buggy address belongs to the object at ffff88802e08ed00 which belongs to the cache skbuff_small_head of size 640 The buggy address is located 194 bytes inside of freed 640-byte region [ffff88802e08ed00, ffff88802e08ef80)

As commit f855691975bb (“xfrm6: Fix the nexthdr offset in _decode_session6.”) showed, xfrm_decode_session was originally intended only for the receive path. IP6CB(skb)->nhoff is not set during transmission. Therefore, set the cb field in the skb to 0 before sending packets.

Details

Affected packages:
kernel @ 5.14.0 (+4 more)

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
AlmaLinux 9.2 ESU Released
12 kernels
  • 5.14.0-284.1101.el9_2.tuxcare.7.els20
  • 5.14.0-284.1101.el9_2.tuxcare.7.els21
  • 5.14.0-284.1101.el9_2.tuxcare.7.els23
  • 5.14.0-284.1101.el9_2.tuxcare.7.els22
  • 5.14.0-284.1101.el9_2.tuxcare.7.els14
  • 5.14.0-284.1101.el9_2.tuxcare.7.els18
  • 5.14.0-284.1101.el9_2.tuxcare.7.els16
  • 5.14.0-284.1101.el9_2.tuxcare.7.els15
  • 5.14.0-284.1101.el9_2.tuxcare.7.els17
  • 5.14.0-284.1101.el9_2.tuxcare.7.els19
  • 5.14.0-284.1101.el9_2.tuxcare.7.els24
  • 5.14.0-284.1101.el9_2.tuxcare.7.els25
Amazon Linux 2 Planned
Amazon Linux 2023 Planned
Amazon Linux 2 5.10 Planned
Amazon Linux 2 5.4 Planned
Debian 12 Planned
RHEL 8 Planned
RHEL8 EUS 8.6 Released
59 kernels
  • 4.18.0-372.51.1.el8_6
  • 4.18.0-372.46.1.el8_6
  • 4.18.0-372.41.1.el8_6
  • 4.18.0-372.36.1.el8_6
  • 4.18.0-372.52.1.el8_6
  • 4.18.0-372.57.1.el8_6
  • 4.18.0-372.64.1.el8_6
  • 4.18.0-372.70.1.el8_6
  • 4.18.0-372.75.1.el8_6
  • 4.18.0-372.80.1.el8_6
  • 4.18.0-372.87.1.el8_6
  • 4.18.0-372.91.1.el8_6
  • 4.18.0-372.93.1.el8_6
  • 4.18.0-372.95.1.el8_6
  • 4.18.0-372.98.1.el8_6
  • 4.18.0-372.100.1.el8_6
  • 4.18.0-372.102.1.el8_6
  • 4.18.0-372.105.1.el8_6
  • 4.18.0-372.107.1.el8_6
  • 4.18.0-372.111.1.el8_6
  • 4.18.0-372.118.1.el8_6
  • 4.18.0-372.119.1.el8_6
  • 4.18.0-372.113.1.el8_6
  • 4.18.0-372.109.1.el8_6
  • 4.18.0-372.115.1.el8_6
  • 4.18.0-372.121.1.el8_6
  • 4.18.0-372.123.1.el8_6
  • 4.18.0-372.124.1.el8_6
  • 4.18.0-372.125.1.el8_6
  • 4.18.0-372.126.1.el8_6
  • 4.18.0-372.127.1.el8_6
  • 4.18.0-372.129.1.el8_6
  • 4.18.0-372.131.1.el8_6
  • 4.18.0-372.133.1.el8_6
  • 4.18.0-372.134.1.el8_6
  • 4.18.0-372.137.1.el8_6
  • 4.18.0-372.139.1.el8_6
  • 4.18.0-372.141.1.el8_6
  • 4.18.0-372.142.1.el8_6
  • 4.18.0-372.143.1.el8_6
  • 4.18.0-372.145.1.el8_6
  • 4.18.0-372.149.1.el8_6
  • 4.18.0-372.150.1.el8_6
  • 4.18.0-372.151.1.el8_6
  • 4.18.0-372.153.1.el8_6
  • 4.18.0-372.155.1.el8_6
  • 4.18.0-372.157.1.el8_6
  • 4.18.0-372.158.1.el8_6
  • 4.18.0-372.160.1.el8_6
  • 4.18.0-372.162.1.el8_6
  • 4.18.0-372.164.1.el8_6
  • 4.18.0-372.166.1.el8_6
  • 4.18.0-372.168.1.el8_6
  • 4.18.0-372.170.1.el8_6
  • 4.18.0-372.172.1.el8_6
  • 4.18.0-372.173.1.el8_6
  • 4.18.0-372.175.1.el8_6
  • 4.18.0-372.177.1.el8_6
  • 4.18.0-372.179.1.el8_6
RHEL 9 Will Not Fix
Ubuntu 20.04 Planned
Ubuntu 22.04 Planned