CVE-2023-53201Incorrect Calculation in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound of the mbox producer index correctly. Currently the wraparound happens once u32 max is reached. Bit 31 of the producer index register is special and should be set only once for the first command. Because the producer index overflow setting bit31 after a long time, FW goes to initialization sequence and this causes FW hang. Fix is to wraparound

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.115.10.188+4
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linux1ac5a404797523cedaf424a3aaa3cf8f9548dff89341501e2f7af29f5b5562c2840a7fde40eb7de4+6
debiandebian/linux< linux 6.1.52-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53201: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound2025-09-15
GHSA
GHSA-p8h3-xc7h-q8r7: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparou2025-09-15

📋Vendor Advisories

2
Red Hat
kernel: RDMA/bnxt_re: wraparound mbox producer index2025-09-15
Debian
CVE-2023-53201: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_r...2023
CVE-2023-53201 — Incorrect Calculation in Linux | cvebase