PT-2025-38373 · Linux+6 · Linux Kernel+6

Published

2023-04-24

·

Updated

2026-03-13

·

CVE-2023-53394

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s net/mlx5e component related to XSK sockets. When a regular request queue (rq) is reactivated after an XSK socket is closed, it may read outdated completion queue entries (cqes), leading to corruption of the rq. This can result in traffic loss on the regular rq and a system crash during subsequent close or deactivation of the rq. The issue was reported as a crash observed when stopping and restarting the xdpsock sample program while traffic is active. The patch resolves this by flushing all cqes during the rq flush process, moving mlx5e rq to ready code into the flush function to facilitate this.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-03278
CVE-2023-53394
ECHO-9C37-FC5E-D30B
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1

Affected Products

Astra Linux
Debian
Linux Kernel
Red Hat
Suse
Mlx5E
Xdpsock