In the Linux kernel, the following vulnerability has been resolved:
crypto: seqiv - Handle EBUSY correctly
As it is seqiv only handles the special return value of EINPROGERSS, which means that in all other cases it will free data related to the request.
However, as the caller of seqiv may specify MAY_BACKLOG, we also need to expect EBUSY and treat it in the same way. Otherwise backlogged requests will trigger a use-after-free.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53373.json"
}[
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ae849d2f48019ff9c104e32bf588ccbfb200e971",
"id": "CVE-2023-53373-2bbb39f3",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1effbddaff60eeef8017c6dea1ee0ed970164d14",
"id": "CVE-2023-53373-300bd235",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63551e4b7cbcd9914258827699eb2cb6ed6e4a16",
"id": "CVE-2023-53373-6f45ba26",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@32e62025e5e52fbe4812ef044759de7010b15dbc",
"id": "CVE-2023-53373-726aab3b",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1effbddaff60eeef8017c6dea1ee0ed970164d14",
"id": "CVE-2023-53373-75de0d81",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4d497e8b200a175094e0ac252ed878add39b8771",
"id": "CVE-2023-53373-7a332db9",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4d497e8b200a175094e0ac252ed878add39b8771",
"id": "CVE-2023-53373-7c148e66",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9477db935eb690f697d9bcc4f608927841bc8b36",
"id": "CVE-2023-53373-8341bdb7",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@32e62025e5e52fbe4812ef044759de7010b15dbc",
"id": "CVE-2023-53373-97a7a29b",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36ec108b7bd7e280edb22de028467bd09d644620",
"id": "CVE-2023-53373-a204ec81",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ae849d2f48019ff9c104e32bf588ccbfb200e971",
"id": "CVE-2023-53373-b7b0518e",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cc4d0d4251748a8a68026938f4055d2ac47c5719",
"id": "CVE-2023-53373-d4df054a",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@cc4d0d4251748a8a68026938f4055d2ac47c5719",
"id": "CVE-2023-53373-e59583ef",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36ec108b7bd7e280edb22de028467bd09d644620",
"id": "CVE-2023-53373-e59ed92e",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"length": 285.0,
"function_hash": "247343881419679083123543325483930646843"
},
"signature_version": "v1",
"target": {
"function": "seqiv_aead_encrypt_complete2",
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9477db935eb690f697d9bcc4f608927841bc8b36",
"id": "CVE-2023-53373-eb335e30",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"236794514223962347622091981058190193011",
"102482235089305759107343975839640376141",
"916411709477225510602334311786730477",
"182716753242136339725463163577676593324"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "crypto/seqiv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@63551e4b7cbcd9914258827699eb2cb6ed6e4a16",
"id": "CVE-2023-53373-ff5ddee8",
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53373.json"