cbcvebase.
CVE-2023-53799
published 2025-12-09

CVE-2023-53799: In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_spawn…

PriorityP422medium4.7
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_spawn expects to be called in process context. However, when an instance is unregistered while it still has active users, the last user may cause the instance to be freed in atomic context. Fix this by delaying the freeing to a work queue.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1c625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1c
linuxlinux>= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 048545d9fc6424b0a11e7e8771225bb9afe09422048545d9fc6424b0a11e7e8771225bb9afe09422
linuxlinux>= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < c4cb61c5f976183c07d16b0071f0c60bc212ef1fc4cb61c5f976183c07d16b0071f0c60bc212ef1f
linuxlinux>= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 867a146690960ac7b89ce40f4ee60dd32eeb1682867a146690960ac7b89ce40f4ee60dd32eeb1682
linuxlinux>= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < c0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26dc0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26d
linuxlinux>= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 9ae4577bc077a7e32c3c7d442c95bc76865c0f179ae4577bc077a7e32c3c7d442c95bc76865c0f17
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 2.6.19 < 5.10.1955.10.195
linuxlinux_kernel>= 5.11.0 < 5.15.1325.15.132
linuxlinux_kernel>= 5.16.0 < 6.1.536.1.53
linuxlinux_kernel>= 6.2.0 < 6.4.166.4.16
linuxlinux_kernel>= 6.5.0 < 6.5.36.5.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.