{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-53484","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-10-01T11:39:39.402Z","datePublished":"2025-10-01T11:42:52.590Z","dateUpdated":"2026-08-05T09:14:18.959Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:14:18.959Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nlib: cpu_rmap: Avoid use after free on rmap->obj array entries\n\nWhen calling irq_set_affinity_notifier() with NULL at the notify\nargument, it will cause freeing of the glue pointer in the\ncorresponding array entry but will leave the pointer in the array. A\nsubsequent call to free_irq_cpu_rmap() will try to free this entry again\nleading to possible use after free.\n\nFix that by setting NULL to the array entry and checking that we have\nnon-zero at the array entry when iterating over the array in\nfree_irq_cpu_rmap().\n\nThe current code does not suffer from this since there are no cases\nwhere irq_set_affinity_notifier(irq, NULL) (note the NULL passed for the\nnotify arg) is called, followed by a call to free_irq_cpu_rmap() so we\ndon't hit and issue. Subsequent patches in this series excersize this\nflow, hence the required fix."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached only through local device-configuration and teardown paths (`ethtool -L`/set-channels, interface down, devlink SF/VF teardown, driver unbind) that drive `irq_cpu_rmap_remove()` and `free_irq_cpu_rmap()`. No remote packet or protocol data reaches `lib/cpu_rmap.c`; the RFS receive path only reads `rmap->near[]`, not the freed glue objects.\nAC:L - The use-after-free is deterministic and requires no race — releasing an IRQ vector leaves a stale `rmap->obj[]` entry that the subsequent `free_irq_cpu_rmap()` walk unconditionally dereferences, and the attacker fully controls the ordering and timing of both steps. `CONFIG_RFS_ACCEL` is `default y` (depends on `RPS`), so the required configuration is the norm on distro kernels, and the unbounded window between free and walk lets the attacker reliably groom the `kmalloc-64` slab.\nPR:L - Triggering requires CAP_NET_ADMIN over the affected netdev (ethtool set-channels, link down, devlink SF removal), which per kernel-CNA guidance scores as Low rather than High. In common SR-IOV/container deployments an mlx5 VF netdev is delegated into a network namespace owned by a user namespace, giving an otherwise unprivileged container-local user exactly this capability over the device.\nUI:N - No victim action is needed; the attacker performs both the IRQ-vector release and the subsequent rmap teardown entirely on their own via device reconfiguration.\nS:U - The freed object, the corrupted state, and the resulting impact are all within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free on a `kmalloc-64` GFP_KERNEL object with an attacker-paced reclaim window, so the freed `struct irq_glue` can be reoccupied with sprayed data; the attacker-controlled `notify.irq` then selects an arbitrary `irq_desc`, and the resulting refcount underflow and indirect `->release` call chain can be leveraged into arbitrary kernel memory disclosure.\nI:H - After reclaiming the freed glue, `irq_set_affinity_notifier(glue->notify.irq, NULL)` performs an arbitrary IRQ-descriptor lookup and issues spurious `kref_put(&old_notify->kref, old_notify->release)` calls on a live notifier, producing refcount underflow, premature free, and an indirect call through a function pointer — a control-flow hijack primitive rather than a mere crash.\nA:H - Even unweaponized, dereferencing the freed glue and passing garbage to `irq_set_affinity_notifier()` corrupts unrelated IRQ descriptor state and oopses/panics the kernel during device teardown, and the double kref_put can prematurely free the cpu_rmap itself."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["lib/cpu_rmap.c"],"versions":[{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"981f339d2905b6a92ef59358158b326493aecac5","status":"affected","versionType":"git"},{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"d1308bd0b24cb1d78fa2747d5fa3e055cc628a48","status":"affected","versionType":"git"},{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"cc2d2b3dbfb0ba57bc027fb7e1121250c50e4000","status":"affected","versionType":"git"},{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"f748e15253833b771acbede14ea98f50831ac289","status":"affected","versionType":"git"},{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"c6ed54dd90698dc0744d669524cc1c122ded8a16","status":"affected","versionType":"git"},{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"c9115f49cf260d24d8b5f2d9a4b63cb31a627bb4","status":"affected","versionType":"git"},{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"67bca5f1d644f4e79b694abd8052a177de81c37f","status":"affected","versionType":"git"},{"version":"896f97ea95c1d29c0520ee0766b66b7f64cb967c","lessThan":"4e0473f1060aa49621d40a113afde24818101d37","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["lib/cpu_rmap.c"],"versions":[{"version":"3.8","status":"affected"},{"version":"0","lessThan":"3.8","status":"unaffected","versionType":"semver"},{"version":"4.14.316","lessThanOrEqual":"4.14.*","status":"unaffected","versionType":"semver"},{"version":"4.19.284","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.244","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.181","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.113","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.30","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.3.4","lessThanOrEqual":"6.3.*","status":"unaffected","versionType":"semver"},{"version":"6.4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"4.14.316"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"4.19.284"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.4.244"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.10.181"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"5.15.113"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.1.30"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.3.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8","versionEndExcluding":"6.4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/981f339d2905b6a92ef59358158b326493aecac5"},{"url":"https://git.kernel.org/stable/c/d1308bd0b24cb1d78fa2747d5fa3e055cc628a48"},{"url":"https://git.kernel.org/stable/c/cc2d2b3dbfb0ba57bc027fb7e1121250c50e4000"},{"url":"https://git.kernel.org/stable/c/f748e15253833b771acbede14ea98f50831ac289"},{"url":"https://git.kernel.org/stable/c/c6ed54dd90698dc0744d669524cc1c122ded8a16"},{"url":"https://git.kernel.org/stable/c/c9115f49cf260d24d8b5f2d9a4b63cb31a627bb4"},{"url":"https://git.kernel.org/stable/c/67bca5f1d644f4e79b694abd8052a177de81c37f"},{"url":"https://git.kernel.org/stable/c/4e0473f1060aa49621d40a113afde24818101d37"}],"title":"lib: cpu_rmap: Avoid use after free on rmap->obj array entries","x_generator":{"engine":"bippy-1.2.0"}}}}