cbcvebase.
CVE-2023-53494
published 2025-10-01

CVE-2023-53494: In the Linux kernel, the following vulnerability has been resolved: crypto: xts - Handle EBUSY correctly As it is xts only handles the special return value of…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: xts - Handle EBUSY correctly As it is xts only handles the special return value of EINPROGRESS, which means that in all other cases it will free data related to the request. However, as the caller of xts may specify MAY_BACKLOG, we also need to expect EBUSY and treat it in the same way. Otherwise backlogged requests will trigger a use-after-free.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 8083b1bf8163e7ae7d8c90f221106d96450b8aa8 < 92a07ba4f0af2cccdc2aa5ee32679c9c9714db9092a07ba4f0af2cccdc2aa5ee32679c9c9714db90
linuxlinux>= 8083b1bf8163e7ae7d8c90f221106d96450b8aa8 < 912eb10b65646ffd222256c78a1c566a3dac177d912eb10b65646ffd222256c78a1c566a3dac177d
linuxlinux>= 8083b1bf8163e7ae7d8c90f221106d96450b8aa8 < 57c3e1d63b63dc0841d41df729297cd7c1c3580857c3e1d63b63dc0841d41df729297cd7c1c35808
linuxlinux>= 8083b1bf8163e7ae7d8c90f221106d96450b8aa8 < d5870848879291700fe6c5257dcb48aadd10425cd5870848879291700fe6c5257dcb48aadd10425c
linuxlinux>= 8083b1bf8163e7ae7d8c90f221106d96450b8aa8 < 51c082514c2dedf2711c99d93c196cc4eedceb4051c082514c2dedf2711c99d93c196cc4eedceb40
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 5.11 < 5.15.995.15.99
linuxlinux_kernel>= 5.16 < 6.1.166.1.16
linuxlinux_kernel>= 5.4 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2 < 6.2.36.2.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.