CVE-2023-53286 is a vulnerability in the Linux kernel's RDMA/mlx5 driver that affects the destruction of Queue Pairs (QP) and Receive Queues (RQ). Previously, the driver ignored firmware destruction failures, leading to the kernel operating under the false assumption that these resources were successfully destroyed, potentially causing system instability and a kernel WARN. The fix ensures that the firmware destruction status is correctly returned to upper layers, allowing for proper error handling. This vulnerability has a CVSS score of 7.8 (High), indicating a significant impact. It is a local vulnerability (AV:L) with low attack complexity (AC:L) and requires low privileges (PR:L). A successful exploit could lead to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H) due to potential kernel panics or system instability. There is currently no evidence of active exploitation for CVE-2023-53286. No public exploit code is available on platforms like Metasploit or ExploitDB, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.10.192CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.128CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.47CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.4.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.