CVE-2023-54235

Linux Kernel - Use-After-Free in PCI/DOE Work Queue Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: PCI/DOE: Fix destroy_work_on_stack() race The following debug object splat was observed in testing: ODEBUG: free active (active state 0) object: 0000000097d23782 object type: work_struct hint: doe_statemachine_work+0x0/0x510 WARNING: CPU: 1 PID: 71 at lib/debugobjects.c:514 debug_print_object+0x7d/0xb0 ... Workqueue: pci 0000:36:00.0 DOE [1 doe_statemachine_work RIP: 0010:debug_print_object+0x7d/0xb0 ... Call Trace: ? debug_print_object+0x7d/0xb0 ? __pfx_doe_statemachine_work+0x10/0x10 debug_object_free.part.0+0x11b/0x150 doe_statemachine_work+0x45e/0x510 process_one_work+0x1d4/0x3c0 This occurs because destroy_work_on_stack() was called after signaling the completion in the calling thread. This creates a race between destroy_work_on_stack() and the task->work struct going out of scope in pci_doe(). Signal the work complete after destroying the work struct. This is safe because signal_task_complete() is the final thing the work item does and the workqueue code is careful not to access the work struct after.

Scores

EPSS 0.0017
EPSS Percentile 7.2%

Details

Status published
Products (16)
linux/Kernel < 6.1.53linux
linux/Kernel 6.2.0 - 6.4.16linux
linux/Kernel 6.3.0 - 6.5.3linux
Linux/Linux < 6.3
Linux/Linux 2a0e0f4773fe8032fb17e56f897bee32ce3cdc2b - d96799ee3b78962c80e4b6653734f488f999ca09
Linux/Linux 6.1.24 - 6.1.53
Linux/Linux 6.1.53 - 6.1.*
Linux/Linux 6.2.11 - 6.3
Linux/Linux 6.3
Linux/Linux 6.4.16 - 6.4.*
... and 6 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026