SB20250919112 - Improper locking in Linux kernel hw mlx5 driver
Published: September 19, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2023-53393)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the do_get_hw_stats() function in drivers/infiniband/hw/mlx5/counters.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/38b50aa44495d5eb4218f0b82fc2da76505cec53
- https://git.kernel.org/stable/c/8d89870d63758363b07ace5c2df82d6bf865f78b
- https://git.kernel.org/stable/c/9a97da4674b890b4c28f5f12beba8c33a9cd2f49
- https://git.kernel.org/stable/c/e597b003c736217b0c99ccf1b240c25009105238
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.5