Junglewise Threat Intelligence

CVE-2023-54269: Linux kernel SUNRPC double free xprt_ctxt memory corruption

CVE-2023-54269 · Severity: critical · CVSS 9.8 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SUNRPC (Sun Remote Procedure Call) subsystem, which handles network-based RPC communication used by services like NFS, contains a memory corruption vulnerability. When RPC requests are deferred twice in rapid succession, the same memory object can be freed twice, causing a system crash or potential code execution. This affects any system running NFS or other RPC-based services.

Technical details

This is a use-after-free/double-free vulnerability in the SUNRPC svc_defer() function (net/sunrpc/svc_xprt.c). The root cause is that when a deferred RPC request is reused, the rq_xprt_ctxt pointer is not consistently cleared before being reused, allowing it to reference already-freed memory. The vulnerable code path occurs when an RPC request is deferred a second time: the transport context pointer from the first deferral remains in the reused svc_deferred_req structure, and when xpo_release_xprt is called, it frees the same context object twice. The vulnerability requires specific RPC usage patterns (rare double-deferral) and affects network-accessible systems running SUNRPC services. The fix ensures rq_xprt_ctxt is always cleared during deferral and adds an assertion to catch the condition.

Affected products

  • Linux Linux kernel multiple versions; fix backported to stable kernels including linux-4.4.y through linux-6.x.y series

Timeline

  • 2023-05-09: disclosed
  • 2023-05-24: patched: Fix backported to stable kernel releases

References

Related threats