{"id":"CVE-2023-52629","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsh: push-switch: Reorder cleanup operations to avoid use-after-free bug\n\nThe original code puts flush_work() before timer_shutdown_sync()\nin switch_drv_remove()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsh: push-switch: Reorder cleanup operations to avoid use-after-free bug\n\nThe original code puts flush_work() before timer_shutdown_sync()\nin switch_drv_remove(). Althou…","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 2.6.20, < 6.5.4"],"patched":["linux_kernel 6.5.4"],"published":"2024-03-29","updated":"2026-10-03","sourceUpdated":"2026-10-03T11:17:26.973","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-52629","references":[{"url":"https://git.kernel.org/stable/c/246f80a0b17f8f582b2c0996db02998239057c65","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/610dbd8ac271aa36080aac50b928d700ee3fe4de","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff635d1f143b55fa005e9e43b16e6d8f677e90a5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/246f80a0b17f8f582b2c0996db02998239057c65","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/610dbd8ac271aa36080aac50b928d700ee3fe4de","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2024-04-01T17:41:22.649775Z"},"epss":0.00242,"epssPercentile":0.13917,"ingestedAt":"2026-10-03T11:43:42.099Z","slug":"CVE-2023-52629","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsh: push-switch: Reorder cleanup operations to avoid use-after-free bug\n\nThe original code puts flush_work() before timer_shutdown_sync()\nin switch_drv_remove(). Although we use flush_work() to stop\nthe worker, it could be rescheduled in switch_timer(). As a result,\na use-after-free bug can occur. The details are shown below:\n\n      (cpu 0)                    |      (cpu 1)\nswitch_drv_remove()              |\n flush_work()                    |\n  ...                            |  switch_timer // timer\n                                 |   schedule_work(&psw->work)\n timer_shutdown_sync()           |\n ...                             |  switch_work_handler // worker\n kfree(psw) // free              |\n                                 |   psw->state = 0 // use\n\nThis patch puts timer_shutdown_sync() before flush_work() to\nmitigate the bugs. As a result, the worker and timer will be\nstopped safely before the deallocate operations.\n\n## Affected\n\n- `linux_kernel >= 2.6.20, < 6.5.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.5.4`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}