Junglewise Threat Intelligence

CVE-2023-54142: Linux kernel GTP use-after-free in __gtp_encap_destroy

CVE-2023-54142 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's GTP (GPRS Tunneling Protocol) networking module contains a use-after-free memory safety bug that allows a local attacker to crash the system or potentially execute code with kernel privileges. The vulnerability occurs when a network interface is destroyed, causing the kernel to access memory that has already been freed, leading to system instability or data corruption.

Technical details

This vulnerability is a use-after-free condition in the __gtp_encap_destroy() function within the GTP networking driver (drivers/net/gtp.c). The root cause is an ordering issue: the function calls release_sock() after sock_put() has already released the final reference count on a socket structure, causing the freed memory to be accessed. A prior commit attempted to fix RCU usage issues by adding lock_sock()/release_sock() calls to protect sk->sk_user_data, but incorrectly placed release_sock() after the reference is dropped. A local attacker can trigger this by crafting network operations that cause a GTP device to be unregistered, leading to a kernel crash detected by KASAN (Kernel Address Sanitizer) as a slab-use-after-free. The fix requires reordering the operations to ensure release_sock() is called before sock_put().

Affected products

  • Linux Linux kernel 6.4.0-rc5 and potentially other versions

Timeline

  • 2025-12-24: disclosed

Related threats