{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2023-54046",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-12-24T12:21:05.089Z",
        "datePublished": "2025-12-24T12:22:57.416Z",
        "dateUpdated": "2026-08-05T09:16:45.094Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T09:16:45.094Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: essiv - Handle EBUSY correctly\n\nAs it is essiv only handles the special return value of EINPROGERSS,\nwhich means that in all other cases it will free data related to the\nrequest.\n\nHowever, as the caller of essiv may specify MAY_BACKLOG, we also need\nto expect EBUSY and treat it in the same way.  Otherwise backlogged\nrequests will trigger a use-after-free."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The essiv AEAD transform is driven only by local paths — dm-crypt block I/O on a locally-mapped encrypted volume, or an AF_ALG socket — with no remote peer parsing attacker data. No network-facing consumer of essiv(aead) exists.\nAC:L - Once a system runs dm-crypt with AEAD+ESSIV over a backlog-queueing crypto accelerator, an attacker can saturate that queue at will with sustained concurrent I/O, so the -EBUSY window is attacker-created rather than incidental.\nPR:L - No capability is required — an unprivileged local user with access to a file on the encrypted volume (or an AF_ALG aead socket) generates the crypto requests that reach essiv_aead_crypt(); dm-crypt setup is pre-existing administrative configuration, not a privilege the attacker must hold.\nUI:N - The vulnerable path is exercised by the attacker's own I/O or socket operations; no victim action is needed beyond the encrypted device already being mapped.\nS:U - The freed buffer and the resulting heap corruption are entirely within the kernel's own memory and security authority, with no crossing into a hypervisor, IOMMU, or other domain.\nC:H - The prematurely freed buffer is still consumed as AAD by the queued request, so reallocated heap contents are read and folded into the authentication tag returned to the caller, and the double-free yields a UAF primitive usable for arbitrary kernel reads.\nI:H - Freeing the same slab pointer two or three times lets an attacker free an object that has since been reallocated, producing overlapping-object type confusion — a well-established route to arbitrary kernel write and control-flow hijack.\nA:H - Use-after-free plus double-free corrupts the SLUB freelist and trips KASAN/BUG_ON, causing kernel oops or panic even when not exploited further."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "crypto/essiv.c"
                    ],
                    "versions": [
                        {
                            "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
                            "lessThan": "c61e7d182ee3f3f5ecf18a2964e303d49c539b52",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
                            "lessThan": "796e02cca30a67322161f0745e5ce994bbe75605",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
                            "lessThan": "840a1d3b77c1b062bd62b4733969a5b1efc274ce",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
                            "lessThan": "a006aa3eedb8bfd6fe317c3cfe9c86ffe76b2385",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
                            "lessThan": "69c67d451fc19d88e54f7d97e8e7c093e08357e1",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "be1eb7f78aa8fbe34779c56c266ccd0364604e71",
                            "lessThan": "b5a772adf45a32c68bef28e60621f12617161556",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "crypto/essiv.c"
                    ],
                    "versions": [
                        {
                            "version": "5.4",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.4",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.235",
                            "lessThanOrEqual": "5.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.173",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.99",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.16",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.2.3",
                            "lessThanOrEqual": "6.2.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.3",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "5.4.235"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "5.10.173"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "5.15.99"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.1.16"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.2.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.3"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/c61e7d182ee3f3f5ecf18a2964e303d49c539b52"
                },
                {
                    "url": "https://git.kernel.org/stable/c/796e02cca30a67322161f0745e5ce994bbe75605"
                },
                {
                    "url": "https://git.kernel.org/stable/c/840a1d3b77c1b062bd62b4733969a5b1efc274ce"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a006aa3eedb8bfd6fe317c3cfe9c86ffe76b2385"
                },
                {
                    "url": "https://git.kernel.org/stable/c/69c67d451fc19d88e54f7d97e8e7c093e08357e1"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b5a772adf45a32c68bef28e60621f12617161556"
                }
            ],
            "title": "crypto: essiv - Handle EBUSY correctly",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}