CVE-2023-53799
published 2025-12-09CVE-2023-53799: In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_spawn…
PriorityP422medium4.7
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
crypto: api - Use work queue in crypto_destroy_instance
The function crypto_drop_spawn expects to be called in process
context. However, when an instance is unregistered while it still
has active users, the last user may cause the instance to be freed
in atomic context.
Fix this by delaying the freeing to a work queue.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1c | 625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1c |
| linux | linux | >= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 048545d9fc6424b0a11e7e8771225bb9afe09422 | 048545d9fc6424b0a11e7e8771225bb9afe09422 |
| linux | linux | >= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < c4cb61c5f976183c07d16b0071f0c60bc212ef1f | c4cb61c5f976183c07d16b0071f0c60bc212ef1f |
| linux | linux | >= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 867a146690960ac7b89ce40f4ee60dd32eeb1682 | 867a146690960ac7b89ce40f4ee60dd32eeb1682 |
| linux | linux | >= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < c0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26d | c0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26d |
| linux | linux | >= 6bfd48096ff8ecabf955958b51ddfa7988eb0a14 < 9ae4577bc077a7e32c3c7d442c95bc76865c0f17 | 9ae4577bc077a7e32c3c7d442c95bc76865c0f17 |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 2.6.19 < 5.10.195 | 5.10.195 |
| linux | linux_kernel | >= 5.11.0 < 5.15.132 | 5.15.132 |
| linux | linux_kernel | >= 5.16.0 < 6.1.53 | 6.1.53 |
| linux | linux_kernel | >= 6.2.0 < 6.4.16 | 6.4.16 |
| linux | linux_kernel | >= 6.5.0 < 6.5.3 | 6.5.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
crypto: api - Use work queue in crypto_destroy_instance
osv·2025-12-09
CVE-2023-53799 crypto: api - Use work queue in crypto_destroy_instance
crypto: api - Use work queue in crypto_destroy_instance
In the Linux kernel, the following vulnerability has been resolved:
crypto: api - Use work queue in crypto_destroy_instance
The function crypto_drop_spawn expects to be called in process
context. However, when an instance is unregistered while it still
has active users, the last user may cause the instance to be freed
in atomic context.
Fix this by delaying the freeing to a work queue.
OSV
CVE-2023-53799: In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_s
osv·2025-12-09
CVE-2023-53799 CVE-2023-53799: In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_s
In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_spawn expects to be called in process context. However, when an instance is unregistered while it still has active users, the last user may cause the instance to be freed in atomic context. Fix this by delaying the freeing to a work queue.
GHSA
GHSA-cp5p-6f9j-7hj2: In the Linux kernel, the following vulnerability has been resolved:
crypto: api - Use work queue in crypto_destroy_instance
The function crypto_drop
ghsa_unreviewed·2025-12-09
CVE-2023-53799 GHSA-cp5p-6f9j-7hj2: In the Linux kernel, the following vulnerability has been resolved:
crypto: api - Use work queue in crypto_destroy_instance
The function crypto_drop
In the Linux kernel, the following vulnerability has been resolved:
crypto: api - Use work queue in crypto_destroy_instance
The function crypto_drop_spawn expects to be called in process
context. However, when an instance is unregistered while it still
has active users, the last user may cause the instance to be freed
in atomic context.
Fix this by delaying the freeing to a work queue.
Red Hat
kernel: crypto: api - Use work queue in crypto_destroy_instance
vendor_redhat·2025-12-09·CVSS 4.7
CVE-2023-53799 [MEDIUM] CWE-368 kernel: crypto: api - Use work queue in crypto_destroy_instance
kernel: crypto: api - Use work queue in crypto_destroy_instance
In the Linux kernel, the following vulnerability has been resolved:
crypto: api - Use work queue in crypto_destroy_instance
The function crypto_drop_spawn expects to be called in process
context. However, when an instance is unregistered while it still
has active users, the last user may cause the instance to be freed
in atomic context.
Fix this by delaying the freeing to a work queue.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Out of support scope
Package: ker
Debian
CVE-2023-53799: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: api...
vendor_debian·2023
CVE-2023-53799 CVE-2023-53799: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: api...
In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_spawn expects to be called in process context. However, when an instance is unregistered while it still has active users, the last user may cause the instance to be freed in atomic context. Fix this by delaying the freeing to a work queue.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
trixie: resolved (fixed in 6.5.3-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/048545d9fc6424b0a11e7e8771225bb9afe09422https://git.kernel.org/stable/c/625bf86bf53eb7a8ee60fb9dc45b272b77e5ce1chttps://git.kernel.org/stable/c/867a146690960ac7b89ce40f4ee60dd32eeb1682https://git.kernel.org/stable/c/9ae4577bc077a7e32c3c7d442c95bc76865c0f17https://git.kernel.org/stable/c/c0dbcebc7f390ec7dbe010dcc22c60f0c6bfc26dhttps://git.kernel.org/stable/c/c4cb61c5f976183c07d16b0071f0c60bc212ef1f
2025-12-09
Published