---
id: CVE-2023-52629
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  sh: push-switch: Reorder cleanup operations to avoid use-after-free bug

  The original code puts flush_work() before timer_shutdown_sync()
  in switch_drv_remove()
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  sh: push-switch: Reorder cleanup operations to avoid use-after-free bug

  The original code puts flush_work() before timer_shutdown_sync()
  in switch_drv_remove(). Althou…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.20, < 6.5.4'
patched:
  - linux_kernel 6.5.4
published: '2024-03-29'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:26.973'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-52629'
references:
  - url: 'https://git.kernel.org/stable/c/246f80a0b17f8f582b2c0996db02998239057c65'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/610dbd8ac271aa36080aac50b928d700ee3fe4de'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ff635d1f143b55fa005e9e43b16e6d8f677e90a5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/246f80a0b17f8f582b2c0996db02998239057c65'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/610dbd8ac271aa36080aac50b928d700ee3fe4de'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-04-01T17:41:22.649775Z'
epss: 0.00242
epssPercentile: 0.13917
ingestedAt: '2026-10-03T11:43:42.099Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

sh: push-switch: Reorder cleanup operations to avoid use-after-free bug

The original code puts flush_work() before timer_shutdown_sync()
in switch_drv_remove(). Although we use flush_work() to stop
the worker, it could be rescheduled in switch_timer(). As a result,
a use-after-free bug can occur. The details are shown below:

      (cpu 0)                    |      (cpu 1)
switch_drv_remove()              |
 flush_work()                    |
  ...                            |  switch_timer // timer
                                 |   schedule_work(&psw->work)
 timer_shutdown_sync()           |
 ...                             |  switch_work_handler // worker
 kfree(psw) // free              |
                                 |   psw->state = 0 // use

This patch puts timer_shutdown_sync() before flush_work() to
mitigate the bugs. As a result, the worker and timer will be
stopped safely before the deallocate operations.

## Affected

- `linux_kernel >= 2.6.20, < 6.5.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.5.4`
