crypto: seqiv - Handle EBUSY correctly
Published Sep 18, 2025
7.8
HIGHCVSS 3.1
EPSS 0.16%
Description
As it is seqiv only handles the special return value of EINPROGERSS, which means that in all other cases it will free data related to the request.
However, as the caller of seqiv may specify MAY_BACKLOG, we also need to expect EBUSY and treat it in the same way. Otherwise backlogged requests will trigger a use-after-free.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.25
Unaffected
- ≥ 0, < 2.6.25
- ≥ 4.14.308, ≤ 4.14.*
- ≥ 4.19.276, ≤ 4.19.*
- ≥ 5.10.173, ≤ 5.10.*
- ≥ 5.15.99, ≤ 5.15.*
- ≥ 5.4.235, ≤ 5.4.*
- ≥ 6.1.16, ≤ 6.1.*
- ≥ 6.2.3, ≤ 6.2.*
- 6.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 2.6.25 · < 4.14.308
- ≥ 4.15 · < 4.19.276
- ≥ 4.20 · < 5.4.235
- ≥ 5.5 · < 5.10.173
- ≥ 5.11 · < 5.15.99
- ≥ 5.16 · < 6.1.16
- ≥ 6.2 · < 6.2.3
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-0:3.10.0-1160.142.1.el7
Fixed · RHSA-2025:21063
Red Hat Enterprise Linux 7 Extended Lifecycle Support
kernel-rt-0:3.10.0-1160.142.1.rt56.1294.el7
Fixed · RHSA-2025:21082
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.80.1.el8_10
Fixed · RHSA-2025:18297
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.80.1.rt7.421.el8_10
Fixed · RHSA-2025:18298
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.178.1.el8_2
Fixed · RHSA-2025:23445
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
kernel-0:4.18.0-305.179.1.el8_4
Fixed · RHSA-2025:22752
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
kernel-0:4.18.0-305.179.1.el8_4
Fixed · RHSA-2025:22752
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
kernel-0:4.18.0-372.168.1.el8_6
Fixed · RHSA-2025:21084
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
kernel-0:4.18.0-372.168.1.el8_6
Fixed · RHSA-2025:21084
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
kernel-0:4.18.0-372.168.1.el8_6
Fixed · RHSA-2025:21084
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
kernel-0:4.18.0-477.118.1.el8_8
Fixed · RHSA-2025:21083
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
kernel-0:4.18.0-477.118.1.el8_8
Fixed · RHSA-2025:21083
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.52.1.el9_6
Fixed · RHSA-2025:17760
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.52.1.el9_6
Fixed · RHSA-2025:17760
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.7.1.el9_7
Fixed · RHSA-2025:21112
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.7.1.el9_7
Fixed · RHSA-2025:21112
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-0:5.14.0-70.151.1.el9_0
Fixed · RHSA-2025:19492
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
kernel-rt-0:5.14.0-70.151.1.rt21.223.el9_0
Fixed · RHSA-2025:19268
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-0:5.14.0-284.146.1.el9_2
Fixed · RHSA-2025:21051
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
kernel-rt-0:5.14.0-284.146.1.rt14.431.el9_2
Fixed · RHSA-2025:21128
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.96.1.el9_4
Fixed · RHSA-2025:19104
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-0:3.10.0-1160.142.1.el7 | Fixed | RHSA-2025:21063 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | kernel-rt-0:3.10.0-1160.142.1.rt56.1294.el7 | Fixed | RHSA-2025:21082 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.80.1.el8_10 | Fixed | RHSA-2025:18297 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.80.1.rt7.421.el8_10 | Fixed | RHSA-2025:18298 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.178.1.el8_2 | Fixed | RHSA-2025:23445 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | kernel-0:4.18.0-305.179.1.el8_4 | Fixed | RHSA-2025:22752 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | kernel-0:4.18.0-305.179.1.el8_4 | Fixed | RHSA-2025:22752 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | kernel-0:4.18.0-372.168.1.el8_6 | Fixed | RHSA-2025:21084 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | kernel-0:4.18.0-372.168.1.el8_6 | Fixed | RHSA-2025:21084 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | kernel-0:4.18.0-372.168.1.el8_6 | Fixed | RHSA-2025:21084 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | kernel-0:4.18.0-477.118.1.el8_8 | Fixed | RHSA-2025:21083 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | kernel-0:4.18.0-477.118.1.el8_8 | Fixed | RHSA-2025:21083 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.52.1.el9_6 | Fixed | RHSA-2025:17760 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.52.1.el9_6 | Fixed | RHSA-2025:17760 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.7.1.el9_7 | Fixed | RHSA-2025:21112 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.7.1.el9_7 | Fixed | RHSA-2025:21112 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-0:5.14.0-70.151.1.el9_0 | Fixed | RHSA-2025:19492 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | kernel-rt-0:5.14.0-70.151.1.rt21.223.el9_0 | Fixed | RHSA-2025:19268 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-0:5.14.0-284.146.1.el9_2 | Fixed | RHSA-2025:21051 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | kernel-rt-0:5.14.0-284.146.1.rt14.431.el9_2 | Fixed | RHSA-2025:21128 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.96.1.el9_4 | Fixed | RHSA-2025:19104 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The flaw is in the seqiv IV generator and can lead to a use-after-free when backlogged crypto requests return -EBUSY. Triggering it is easier locally by flooding the kernel crypto API (e.g. via AF_ALG or many concurrent AEAD requests) because the attacker must create backlog conditions. Remote triggering is much harder and only realistic for specific configurations (for example an in-kernel IPsec/TLS path that uses seqiv for AEAD). In practice this means an unprivileged local user with access to the kernel crypto interface is the most likely threat vector, while a remote attacker would need the target to both use seqiv and be inducible into heavy crypto backlog.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-53373 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2396379 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-29968 Advisory
- https://git.kernel.org/stable/c/1effbddaff60eeef8017c6dea1ee0ed970164d14 Patch
- https://git.kernel.org/stable/c/32e62025e5e52fbe4812ef044759de7010b15dbc Patch
- https://git.kernel.org/stable/c/36ec108b7bd7e280edb22de028467bd09d644620 Patch
- https://git.kernel.org/stable/c/4d497e8b200a175094e0ac252ed878add39b8771 Patch
- https://git.kernel.org/stable/c/63551e4b7cbcd9914258827699eb2cb6ed6e4a16 Patch
- https://git.kernel.org/stable/c/9477db935eb690f697d9bcc4f608927841bc8b36 Patch
- https://git.kernel.org/stable/c/ae849d2f48019ff9c104e32bf588ccbfb200e971 Patch
- https://git.kernel.org/stable/c/cc4d0d4251748a8a68026938f4055d2ac47c5719 Patch
- https://lore.kernel.org/linux-cve-announce/2025091855-CVE-2023-53373-087e@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53373
- https://www.cve.org/CVERecord?id=CVE-2023-53373
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data