PT-2025-43121 · Mlx5 Core+2 · Mlx5 Core+2

Published

2023-04-20

·

Updated

2025-10-23

·

CVE-2023-53720

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue in the net/mlx5e component where the label mapping is not correctly released when replacing an existing connection tracking (ct) entry. This leads to a memory leak. The backtrace indicates the issue occurs during the processing of network flows, specifically within the mlx5 tc ct entry create mod hdr and mlx5 tc ct block flow offload functions. The mapping add function within the mlx5 core module is also implicated in the memory leak.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03887
CVE-2023-53720

Affected Products

Linux Kernel
Mlx5 Core
Mlx5E