Junglewise Threat Intelligence

CVE-2023-53810: Linux kernel blk-mq crypto keyslot use-after-free race condition

CVE-2023-53810 · Severity: high · CVSS 7.8 · Published 2025-12-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's block I/O subsystem (blk-mq) has a race condition in its inline encryption support that can lead to use-after-free errors. When filesystems complete encrypted I/O operations, the kernel may free encryption keys while they are still in use by the block layer, causing kernel crashes or memory corruption. This issue is particularly common with full-disk encryption (fscrypt) on modern systems.

Technical details

The vulnerability is a race condition in the block layer's crypto keyslot management (blk-crypto). The root cause is that blk_crypto_put_keyslot() is called after bio_endio(), but filesystems can call blk_crypto_evict_key() immediately after receiving the I/O completion notification. This causes __blk_crypto_evict_key() to observe non-zero slot_refs and bail out without evicting the key, leading to use-after-free in blk_crypto_reprogram_all_keys(). The fix moves the keyslot release (blk_crypto_rq_put_keyslot) to occur before bio_endio() completes, ensuring the keyslot is released before upper layers are notified of completion. The vulnerability affects systems using per-file encryption keys with fscrypt, though the race window is narrow and exploitation is rare.

Affected products

  • Linux Linux kernel 5.0 through 6.2 (approximately; varies by stable branch)

Timeline

  • 2023-05-03: disclosed: Patch authored by Eric Biggers
  • 2023-05-11: patched: Merged into stable kernel trees via Greg Kroah-Hartman

References

Related threats