CVE-2023-52629

Executive Summary

CVE-2023-52629 exposes a use‑after‑free in the Linux kernel’s switch driver. The original code called flush_work() before timer_shutdown_sync(), allowing the timer to reschedule work that accessed freed memory, potentially causing a kernel crash or privilege escalation. The patch reorders cleanup, shutting down the timer before flushing work, ensuring safe deallocation. This mitigates the vulnerability and prevents arbitrary code execution at kernel level.


Authoritative CVE Metadata - CVSS Base Score: 8.4 (HIGH) - Published: 2024-03-29T10:15:09.327 - Last Modified: 2026-10-03T11:17:26.973

Original Description: In the Linux kernel, the following vulnerability has been resolved:

sh: push-switch: Reorder cleanup operations to avoid use-after-free bug

The original code puts flush_work() before timer_shutdown_sync() in switch_drv_remove(). Although we use flush_work() to stop the worker, it could be rescheduled in switch_timer(). As a result, a use-after-free bug can occur. The details are shown below:

  (cpu 0)                    |      (cpu 1)

switch_drv_remove() | flush_work() | ... | switch_timer // timer | schedule_work(&psw->work) timer_shutdown_sync() | ... | switch_work_handler // worker kfree(psw) // free | | psw->state = 0 // use

This patch puts timer_shutdown_sync() before flush_work() to mitigate the bugs. As a result, the worker and timer will be stopped safely before the deallocate operations.

"Don't ruin the present with the ruined past."

— Ellen Gilchrist
Source: NVD