PT-2025-40681 · Linux+6 · Linux Kernel+6

Published

2024-04-30

·

Updated

2026-04-20

·

CVE-2023-53539

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Linux kernel’s RDMA/rxe component where incomplete state saving in the rxe requester() function can lead to corrupted resent packets under heavy stress testing. Specifically, when a send packet is dropped by the IP layer, the attempt to resend the packet fails to fully restore the state of the work queue element (WQE), particularly the dma struct used for processing the scatter-gather element (SGE) table. This incomplete restoration results in data corruption during resending. The issue occurs when many queues are sending large messages to a slower node, causing packets to be dropped and subsequently resent with incorrect data. The rxe xmit packet() function can fail with an error code of -EAGAIN, triggering the incomplete state restoration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

ALSA-2025:22800
ALSA-2025:22801
ALSA-2025_16880
ALSA-2025_22800
ALSA-2025_22801
AZL-77396
CVE-2023-53539
RHSA-2024:2394
RHSA-2024_2394
RHSA-2025:22800
RHSA-2025:22801
RHSA-2026:0534
RHSA-2026:0535
RHSA-2026:10756
RHSA-2026:1445
RHSA-2026:1494
RHSA-2026:1495
RHSA-2026:2664
RHSA-2026:3360
RHSA-2026:5691
RHSA-2026:9870
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4301-1
SUSE-SU-2025:4320-1

Affected Products

Almalinux
Centos
Debian
Linux Kernel
Red Hat
Rocky Linux
Suse