CVE-2023-53799
In the Linux kernel, the following vulnerability has been resolved:
crypto: api - Use work queue in crypto_destroy_instance
The function crypto_drop_spawn expects to be called in process context. However, when an instance is unregistered while it still has active users, the last user may cause the instance to be freed in atomic context.
Fix this by delaying the freeing to a work queue.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/048545d9fc6424b0a11e7e8771225bb9afe09422
- https://git.kernel.org/stable/c/625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1c
- https://git.kernel.org/stable/c/867a146690960ac7b89ce40f4ee60dd32eeb1682
- https://git.kernel.org/stable/c/9ae4577bc077a7e32c3c7d442c95bc76865c0f17
- https://git.kernel.org/stable/c/c0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26d
- https://git.kernel.org/stable/c/c4cb61c5f976183c07d16b0071f0c60bc212ef1f
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-53799",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6bfd48096ff8ecabf955958b51ddfa7988eb0a14",
"lessThan": "625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1c",
"versionType": "git"
},
{
"status": "affected",
"version": "6bfd48096ff8ecabf955958b51ddfa7988eb0a14",
"lessThan": "048545d9fc6424b0a11e7e8771225bb9afe09422",
"versionType": "git"
},
{
"status": "affected",
"version": "6bfd48096ff8ecabf955958b51ddfa7988eb0a14",
"lessThan": "c4cb61c5f976183c07d16b0071f0c60bc212ef1f",
"versionType": "git"
},
{
"status": "affected",
"version": "6bfd48096ff8ecabf955958b51ddfa7988eb0a14",
"lessThan": "867a146690960ac7b89ce40f4ee60dd32eeb1682",
"versionType": "git"
},
{
"status": "affected",
"version": "6bfd48096ff8ecabf955958b51ddfa7988eb0a14",
"lessThan": "c0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26d",
"versionType": "git"
},
{
"status": "affected",
"version": "6bfd48096ff8ecabf955958b51ddfa7988eb0a14",
"lessThan": "9ae4577bc077a7e32c3c7d442c95bc76865c0f17",
"versionType": "git"
}
],
"programFiles": [
"crypto/algapi.c",
"include/crypto/algapi.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.195",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.132",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.53",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.4.16",
"versionType": "semver",
"lessThanOrEqual": "6.4.*"
},
{
"status": "unaffected",
"version": "6.5.3",
"versionType": "semver",
"lessThanOrEqual": "6.5.*"
},
{
"status": "unaffected",
"version": "6.6",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"crypto/algapi.c",
"include/crypto/algapi.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-09T01:16:51.597",
"references": [
{
"url": "https://git.kernel.org/stable/c/048545d9fc6424b0a11e7e8771225bb9afe09422",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/867a146690960ac7b89ce40f4ee60dd32eeb1682",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9ae4577bc077a7e32c3c7d442c95bc76865c0f17",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c4cb61c5f976183c07d16b0071f0c60bc212ef1f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: api - Use work queue in crypto_destroy_instance\n\nThe function crypto_drop_spawn expects to be called in process\ncontext. However, when an instance is unregistered while it still\nhas active users, the last user may cause the instance to be freed\nin atomic context.\n\nFix this by delaying the freeing to a work queue."
}
],
"lastModified": "2026-06-17T06:46:05.640",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}