Executive brief
The Linux kernel's block layer encryption (blk-crypto) module contains a use-after-free vulnerability in its key eviction logic. When the blk_crypto_evict_key() function encounters an error during key cleanup (such as a hardware failure or lingering I/O), it previously left the key linked to internal management structures while still allowing callers to free the key object. This can lead to memory corruption and potential system crashes or privilege escalation when the freed key is subsequently referenced.
Technical details
The vulnerability is a use-after-free in the Linux kernel's blk-crypto subsystem, specifically in the blk_crypto_evict_key() function. When key eviction fails (due to a hardware issue, driver bug, or I/O still using the key), the function previously returned an error while leaving the key linked in the keyslot management structures. However, the calling code (e.g., inode eviction paths) does not check the return value and proceeds to free the blk_crypto_key structure immediately. Subsequent calls to blk_crypto_reprogram_all_keys() attempt to access the freed key, causing a use-after-free condition. The fix ensures that blk_crypto_evict_key() unlinks the key from management structures even on failure, preventing the dangling reference. This is a kernel-level vulnerability affecting local attackers with I/O access.
Affected products
- Linux Linux kernel Affected versions include Linux 5.x through 6.x kernels with blk-crypto support; patch applied in 2023-05
Timeline
- 2023-05-03: disclosed: Fix commit by Eric Biggers
- 2023-05-11: patched: Patch merged into stable kernel trees
- 2025-10-04: other: CVE-2023-53536 assigned and published to NVD