CVE-2023-53587

CVE-2023-53587 is a high-severity use after free vulnerability. No fixed version is listed yet.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Sync IRQ works...

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Sync IRQ works before buffer destruction

If something was written to the buffer just before destruction,
it may be possible (maybe not in a real system, but it did
happen in ARCH=um with time-travel) to destroy the ringbuffer
before the IRQ work ran, leading this KASAN report (or a crash
without KASAN):

BUG: KASAN: slab-use-after-free in irq_work_run_list+0x11a/0x13a
Read of size 8 at addr 000000006d640a48 by task swapper/0

CPU: 0 PID: 0 Comm: swapper Tainted: G        W  O       6.3.0-rc1 #7
Stack:
 60c4f20f 0c203d48 41b58ab3 60f224fc
 600477fa 60f35687 60c4f20f 601273dd
 00000008 6101eb00 6101eab0 615be548
Call Trace:
 [<60047a58>] show_stack+0x25e/0x282
 [<60c609e0>] dump_stack_lvl+0x96/0xfd
 [<60c50d4c>] print_report+0x1a7/0x5a8
 [<603078d3>] kasan_report+0xc1/0xe9
 [<60308950>] __asan_report_load8_noabort+0x1b/0x1d
 [<60232844>] irq_work_run_list+0x11a/0x13a
 [<602328b4>] irq_work_tick+0x24/0x34
 [<6017f9dc>] update_process_times+0x162/0x196
 [<6019f335>] tick_sched_handle+0x1a4/0x1c3
 [<6019fd9e>] tick_sched_timer+0x79/0x10c
 [<601812b9>] __hrtimer_run_queues.constprop.0+0x425/0x695
 [<60182913>] hrtimer_interrupt+0x16c/0x2c4
 [<600486a3>] um_timer+0x164/0x183
 [...]

Allocated by task 411:
 save_stack_trace+0x99/0xb5
 stack_trace_save+0x81/0x9b
 kasan_save_stack+0x2d/0x54
 kasan_set_track+0x34/0x3e
 kasan_save_alloc_info+0x25/0x28
 ____kasan_kmalloc+0x8b/0x97
 __kasan_kmalloc+0x10/0x12
 __kmalloc+0xb2/0xe8
 load_elf_phdrs+0xee/0x182
 [...]

The buggy address belongs to the object at 000000006d640800
 which belongs to the cache kmalloc-1k of size 1024
The buggy address is located 584 bytes inside of
 freed 1024-byte region [000000006d640800, 000000006d640c00)

Add the appropriate irq_work_sync() so the work finishes before
the buffers are destroyed.

Prior to the commit in the Fixes tag below, there was only a
single global IRQ work, so this issue didn't exist.

Impact

Memory is accessed after it has been freed, leading to undefined behavior in native code. Typical impact: memory corruption, crash, or potential code execution.

CVE-2023-53587 has a CVSS score of 7.8 (High). The vector is requires local access, low privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. No fixed version is listed yet, so configuration controls and monitoring matter more in the interim.

Affected versions

Not available

Security releases

Not available

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

Not available

Frequently Asked Questions

  1. What is CVE-2023-53587? CVE-2023-53587 is a high-severity use after free vulnerability. No fixed version is listed yet. Memory is accessed after it has been freed, leading to undefined behavior in native code.
  2. How severe is CVE-2023-53587? CVE-2023-53587 has a CVSS score of 7.8 (High). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
  3. Is there a fix for CVE-2023-53587? No fixed version is listed for CVE-2023-53587 yet. Monitor the advisory for updates and apply mitigations in the interim.
  4. Is CVE-2023-53587 exploitable, and should I be worried? Whether CVE-2023-53587 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  5. What actually determines whether CVE-2023-53587 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.

Stop the waste.
Protect your environment with Kodem.