{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-53800","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-12-08T23:58:35.275Z","datePublished":"2025-12-09T00:00:56.507Z","dateUpdated":"2026-08-05T09:16:05.119Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:16:05.119Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nubi: Fix use-after-free when volume resizing failed\n\nThere is an use-after-free problem reported by KASAN:\n  ==================================================================\n  BUG: KASAN: use-after-free in ubi_eba_copy_table+0x11f/0x1c0 [ubi]\n  Read of size 8 at addr ffff888101eec008 by task ubirsvol/4735\n\n  CPU: 2 PID: 4735 Comm: ubirsvol\n  Not tainted 6.1.0-rc1-00003-g84fa3304a7fc-dirty #14\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),\n  BIOS 1.14.0-1.fc33 04/01/2014\n  Call Trace:\n   <TASK>\n   dump_stack_lvl+0x34/0x44\n   print_report+0x171/0x472\n   kasan_report+0xad/0x130\n   ubi_eba_copy_table+0x11f/0x1c0 [ubi]\n   ubi_resize_volume+0x4f9/0xbc0 [ubi]\n   ubi_cdev_ioctl+0x701/0x1850 [ubi]\n   __x64_sys_ioctl+0x11d/0x170\n   do_syscall_64+0x35/0x80\n   entry_SYSCALL_64_after_hwframe+0x46/0xb0\n   </TASK>\n\nWhen ubi_change_vtbl_record() returns an error in ubi_resize_volume(),\n\"new_eba_tbl\" will be freed on error handing path, but it is holded\nby \"vol->eba_tbl\" in ubi_eba_replace_table(). It means that the liftcycle\nof \"vol->eba_tbl\" and \"vol\" are different, so when resizing volume in\nnext time, it causing an use-after-free fault.\n\nFix it by not freeing \"new_eba_tbl\" after it replaced in\nubi_eba_replace_table(), while will be freed in next volume resizing."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable code is reached only through `ioctl(UBI_IOCRSVOL)` on the local `/dev/ubiN` character device (`ubi_cdev_ioctl`, cdev.c:972), or via autoresize at device attach. There is no network- or adjacent-reachable path into `ubi_resize_volume()`.\nAC:L - The failing step is attacker-inducible without hardware faults — `ubi_change_vtbl_record()` propagates `-ENOMEM` from the `GFP_NOFS` allocations in `ubi_eba_atomic_leb_change()` and `ltree_add_entry()`, which memory pressure reliably defeats, and the ioctl can simply be retried until one attempt fails. The resulting dangling `vol->eba_tbl` persists indefinitely, so the attacker has an unbounded window to groom the kmalloc-8/16 slab before firing the read/write.\nPR:L - The path is gated by `capable(CAP_SYS_RESOURCE)`, a single narrow capability commonly delegated to non-root storage/service accounts on the embedded and IoT systems where UBI is deployed, far short of full administrative control of the system. This matches the CISA-ADP scoring of PR:L for the identical sibling bugs CVE-2022-49388 and CVE-2021-47634 in the same UBI cdev ioctl paths.\nUI:N - The attacker performs the resize ioctl, the memory-pressure setup, the heap spray and the subsequent LEB operation entirely on their own. No victim action or interaction is required at any point.\nS:U - The freed object and all corruption sites lie within the kernel's own memory and security authority; there is no VM, IOMMU, or sandbox boundary crossed. Exploitation yields kernel privilege escalation within the same authority.\nC:H - Once the freed 8-byte table is reclaimed with sprayed data, the attacker controls the `entries` pointer, and read sites such as `eba.c:108/458/603/953/1026` dereference `entries[lnum].pnum` with an attacker-chosen `lnum`, yielding an arbitrary kernel-memory read primitive.\nI:H - The write sites `vol->eba_tbl->entries[lnum].pnum = pnum` (eba.c:466, 528, 862, 975, 1464) become a controlled 4-byte write at an attacker-chosen kernel address once the freed slot is reclaimed, sufficient for control-flow hijack and privilege escalation.\nA:H - Even unexploited, the dangling `vol->eba_tbl` is dereferenced by every subsequent LEB operation, by the background wear-leveling worker (`ubi_eba_copy_leb`), and by any UBIFS/ubiblock stacked on the volume, producing kernel oops/panic as shown in the KASAN report in the fix commit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mtd/ubi/vmt.c"],"versions":[{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"bf9875aa7f7d624a8c084425b14bf7e5907ebc30","status":"affected","versionType":"git"},{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"bf795ebbb9995e2fe7945de71177f01c2f1215dc","status":"affected","versionType":"git"},{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"9c8be1f165baee53b5a36ea0b3c9281d403a1d0b","status":"affected","versionType":"git"},{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"35f8d4064e54c18424db2997059d4c0b1d13d093","status":"affected","versionType":"git"},{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"53818746e549e61841428892a8d94344494be797","status":"affected","versionType":"git"},{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"b0c951742348d216f094d16ed4f70ae73db881c0","status":"affected","versionType":"git"},{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"3d6378f7056ac7350338f941001162a8f660853c","status":"affected","versionType":"git"},{"version":"801c135ce73d5df1caf3eca35b66a10824ae0707","lessThan":"9af31d6ec1a4be4caab2550096c6bd2ba8fba472","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mtd/ubi/vmt.c"],"versions":[{"version":"2.6.22","status":"affected"},{"version":"0","lessThan":"2.6.22","status":"unaffected","versionType":"semver"},{"version":"4.14.308","lessThanOrEqual":"4.14.*","status":"unaffected","versionType":"semver"},{"version":"4.19.276","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.235","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.173","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.100","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.18","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.5","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"4.14.308"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"4.19.276"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"5.4.235"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"5.10.173"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"5.15.100"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"6.1.18"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"6.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"6.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bf9875aa7f7d624a8c084425b14bf7e5907ebc30"},{"url":"https://git.kernel.org/stable/c/bf795ebbb9995e2fe7945de71177f01c2f1215dc"},{"url":"https://git.kernel.org/stable/c/9c8be1f165baee53b5a36ea0b3c9281d403a1d0b"},{"url":"https://git.kernel.org/stable/c/35f8d4064e54c18424db2997059d4c0b1d13d093"},{"url":"https://git.kernel.org/stable/c/53818746e549e61841428892a8d94344494be797"},{"url":"https://git.kernel.org/stable/c/b0c951742348d216f094d16ed4f70ae73db881c0"},{"url":"https://git.kernel.org/stable/c/3d6378f7056ac7350338f941001162a8f660853c"},{"url":"https://git.kernel.org/stable/c/9af31d6ec1a4be4caab2550096c6bd2ba8fba472"}],"title":"ubi: Fix use-after-free when volume resizing failed","x_generator":{"engine":"bippy-1.2.0"}}}}