Junglewise Threat Intelligence

CVE-2023-53790: Linux kernel BPF memory allocator use-after-free in hash table maps

CVE-2023-53790 · Severity: high · CVSS 7.8 · Published 2025-12-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's BPF (eBPF) memory allocator used by hash table maps failed to properly zero out memory when reusing freed objects, causing concurrent access to uninitialized synchronization primitives like spin locks. This could allow unprivileged BPF programs or syscalls to trigger hard lockups, resulting in a complete system freeze and denial of service.

Technical details

The vulnerability is a use-after-free / race condition in the BPF memory allocator (kernel/bpf/memalloc.c) affecting non-preallocated hash table maps. When memory containing special BPF map fields (e.g., bpf_spin_lock) is freed and immediately reused, the allocator did not zero the memory before reassignment. Concurrent BPF programs or syscalls could then access partially reinitialized fields, causing hard lockups when attempting to acquire locks on uninitialized spin lock structures. The fix applies __GFP_ZERO flag to ensure allocated objects are zeroed before use in the BPF memory allocator, similar to the already-correct preallocated case. No authentication is required; the vulnerability is exploitable by any process capable of loading/executing BPF programs or invoking BPF syscalls.

Affected products

  • Linux Linux kernel 5.0 through 6.1 and later versions prior to fix

Timeline

  • 2023-02-15: disclosed: Upstream fix commit 997849c4b969034e225153f41026657def66d286 authored
  • 2023-03-10: patched: Patch applied to stable kernel trees

References

Related threats