{"id":"DEBIAN-CVE-2023-53557","details":"In the Linux kernel, the following vulnerability has been resolved:  fprobe: Release rethook after the ftrace_ops is unregistered  While running bpf selftests it's possible to get following fault:    general protection fault, probably for non-canonical address \\   0x6b6b6b6b6b6b6b6b: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC NOPTI   ...   Call Trace:    \u003cTASK\u003e    fprobe_handler+0xc1/0x270    ? __pfx_bpf_testmod_init+0x10/0x10    ? __pfx_bpf_testmod_init+0x10/0x10    ? bpf_fentry_test1+0x5/0x10    ? bpf_fentry_test1+0x5/0x10    ? bpf_testmod_init+0x22/0x80    ? do_one_initcall+0x63/0x2e0    ? rcu_is_watching+0xd/0x40    ? kmalloc_trace+0xaf/0xc0    ? do_init_module+0x60/0x250    ? __do_sys_finit_module+0xac/0x120    ? do_syscall_64+0x37/0x90    ? entry_SYSCALL_64_after_hwframe+0x72/0xdc    \u003c/TASK\u003e  In unregister_fprobe function we can't release fp-\u003erethook while it's possible there are some of its users still running on another cpu.  Moving rethook_free call after fp-\u003eops is unregistered with unregister_ftrace_function call.","modified":"2026-09-15T09:02:51.752573889Z","published":"2025-10-04T16:15:51.050Z","upstream":["CVE-2023-53557"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53557"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.52-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53557.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53557.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53557.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}