PT-2025-41098 · Linux+4 · Linux Kernel+5

Published

2025-05-13

·

Updated

2025-11-28

·

CVE-2023-53654

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the octeontx2-af driver related to the handling of MAC blocks during RVU driver initialization. The driver incorrectly assumes contiguity of LMAC and CGX blocks, leading to potential kernel panics when accessing these blocks with their IDs, particularly with the introduction of new MAC blocks like CN10K RPM and CN10KB RPM USX. The issue is addressed by adding validation checks before accessing CGX and lmac. The crash occurs in the cgx lmac read function, called from rvu program channels.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
CVE-2023-53654
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1

Affected Products

Cn10K Rpm
Cn10Kb Rpm Usx
Linux Kernel
Red Hat
Suse
Octeontx2-Af