PT-2025-40744 · Net/Mlx5E+4 · Net/Mlx5E+4

Published

2020-04-28

·

Updated

2025-12-04

·

CVE-2023-53581

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.4.0-rc4+
Description The Linux kernel contained a flaw in the net/mlx5e module where a race condition could occur during flow removal from the unready flows list. This happened because the check for the NOT READY flag was performed before acquiring the necessary lock. This could lead to a double-removal from the list and a subsequent crash. The issue was fixed by moving the flag check inside the section protected by the uplink priv->unready flows lock mutex.
Recommendations Update to a newer version of the Linux kernel that contains the fix for this vulnerability.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
CESA-2020_1769
CESA-2024_3138
CVE-2023-53581
RHSA-2020:1769
RHSA-2020_1769
RHSA-2024:2394
RHSA-2024:3138
RHSA-2024_2394
RHSA-2024_3138
RHSA-2026:0537
RHSA-2026:0576
RHSA-2026:1441
RHSA-2026:1443
RHSA-2026:1445
RHSA-2026:2490
RHSA-2026:2664
RHSA-2026:3360
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4301-1
SUSE-SU-2025:4320-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse
Net/Mlx5E