Junglewise Threat Intelligence

CVE-2023-53599: Linux kernel af_alg missing initialization in gcm-aes-s390

CVE-2023-53599 · Severity: high · CVSS 7.8 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's cryptographic socket interface (af_alg) fails to properly initialize a critical data structure when handling AES-GCM encryption on s390x systems. When an empty ciphertext is processed, this uninitialized pointer causes the kernel to crash, resulting in a denial of service. This affects systems relying on hardware-accelerated AES-GCM encryption for secure communications.

Technical details

This is a missing initialization vulnerability in the af_alg module's af_alg_alloc_areq() function. The areq->first_rsgl.sgl.sgt.sgl field is not initialized to point to the scatterlist array, causing a null/invalid pointer dereference when the gcm-aes-s390 driver calls gcm_walk_start() on an empty ciphertext. The root cause occurs when af_alg_get_rsgl() bypasses initialization for empty input, leaving req->dst pointing to an uninitialized memory location. The attack is local and requires the ability to send a crafted AEAD request via the af_alg socket interface; no authentication or elevated privileges are required. A successful exploit triggers a kernel oops, resulting in denial of service. The fix initializes the scatterlist pointer correctly in af_alg_alloc_areq().

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2025-10-04: disclosed

Related threats