SB20251230253 - Improper locking in Linux kernel hw irdma driver
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2023-54292)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the irdma_free_cqp_request(), irdma_free_pending_cqp_request() and irdma_wait_event() functions in drivers/infiniband/hw/irdma/utils.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5986e96be7d0b82e50a9c6b019ea3f1926fd8764
- https://git.kernel.org/stable/c/b8b90ba636e3861665aef9a3eab5fcf92839a2c5
- https://git.kernel.org/stable/c/c5b5dbcbf91f769b8eb25f88e32a1522f920f37a
- https://git.kernel.org/stable/c/f0842bb3d38863777e3454da5653d80b5fde6321
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.124
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.43
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5