Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53286

24
FAUCET Score

CVE-2023-53286 is a vulnerability in the Linux kernel's RDMA/mlx5 driver that affects the destruction of Queue Pairs (QP) and Receive Queues (RQ). Previously, the driver ignored firmware destruction failures, leading to the kernel operating under the false assumption that these resources were successfully destroyed, potentially causing system instability and a kernel WARN. The fix ensures that the firmware destruction status is correctly returned to upper layers, allowing for proper error handling. This vulnerability has a CVSS score of 7.8 (High), indicating a significant impact. It is a local vulnerability (AV:L) with low attack complexity (AC:L) and requires low privileges (PR:L). A successful exploit could lead to high confidentiality, integrity, and availability impacts (C:H/I:H/A:H) due to potential kernel panics or system instability. There is currently no evidence of active exploitation for CVE-2023-53286. No public exploit code is available on platforms like Metasploit or ExploitDB, and there is minimal community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.10.192CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.128CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.47CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.4.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 18th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2023-53286Moderate

kernel: RDMA/mlx5: Return the firmware result upon destroying QP/RQ

Sep 16, 2025

References

git.kernel.org / stable/c/04704c201bb08efaf96d7b1396c6864f8984e244
Patch
git.kernel.org / stable/c/1a650d3ccd79cdd5796edd864683a6b8dd0bf576
Patch
git.kernel.org / stable/c/22664c06e997087fe37f9ba208008c948571214a
Patch
git.kernel.org / stable/c/5fe7815e784bf21061885f8112a7108aef5c45bd
Patch
git.kernel.org / stable/c/73311dd831858d797cf8ebe140654ed519b41c36
Patch