CVE-2023-53504
BaseFortify
Publication date: 2025-10-01
Last updated on: 2025-10-02
Assigner: kernel.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | From 5.15.160 (inc) to 5.16 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in the Linux kernel involves improper ordering of the function ib_device_unalloc() in the RDMA/bnxt_re driver. The function ib_dealloc_device() was being called before the device cleanup was completed, which could lead to a use-after-free (UAF) condition. The fix ensures that ib_dealloc_device() is called only after the device cleanup, preventing the UAF issue.
How can this vulnerability impact me? :
The vulnerability could lead to a use-after-free condition in the Linux kernel's RDMA/bnxt_re driver, which may cause system instability, crashes, or potentially allow an attacker to execute arbitrary code or cause denial of service. The exact impact depends on the environment and how the affected driver is used.