SB20250916345 - Resource management error in Linux kernel hw mlx5 driver
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2023-53286)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the mlx5_core_destroy_qp(), mlx5_core_xrcd_dealloc() and mlx5_core_destroy_rq_tracked() functions in drivers/infiniband/hw/mlx5/qpc.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04704c201bb08efaf96d7b1396c6864f8984e244
- https://git.kernel.org/stable/c/1a650d3ccd79cdd5796edd864683a6b8dd0bf576
- https://git.kernel.org/stable/c/22664c06e997087fe37f9ba208008c948571214a
- https://git.kernel.org/stable/c/5fe7815e784bf21061885f8112a7108aef5c45bd
- https://git.kernel.org/stable/c/73311dd831858d797cf8ebe140654ed519b41c36
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.192