CVE-2023-53826

Linux Kernel - Use-After-Free in UBI Wear-Leveling Entry via eraseblk_count_seq_show

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show() Wear-leveling entry could be freed in error path, which may be accessed again in eraseblk_count_seq_show(), for example: __erase_worker eraseblk_count_seq_show wl = ubi->lookuptbl[*block_number] if (wl) wl_entry_destroy ubi->lookuptbl[e->pnum] = NULL kmem_cache_free(ubi_wl_entry_slab, e) erase_count = wl->ec // UAF! Wear-leveling entry updating/accessing in ubi->lookuptbl should be protected by ubi->wl_lock, fix it by adding ubi->wl_lock to serialize wl entry accessing between wl_entry_destroy() and eraseblk_count_seq_show(). Fetch a reproducer in [Link].

Scores

EPSS 0.0022
EPSS Percentile 13.1%

Details

Status published
Products (25)
linux/Kernel 2.6.22 - 4.14.308linux
linux/Kernel 4.15.0 - 4.19.276linux
linux/Kernel 4.20.0 - 5.4.235linux
linux/Kernel 5.11.0 - 5.15.100linux
linux/Kernel 5.16.0 - 6.1.18linux
linux/Kernel 5.5.0 - 5.10.173linux
linux/Kernel 6.2.0 - 6.2.5linux
Linux/Linux < 2.6.22
Linux/Linux 2.6.22
Linux/Linux 4.14.308 - 4.14.*
... and 15 more
Published Dec 09, 2025
Tracked Since Feb 18, 2026