CVE-2023-53201
published 2025-09-15CVE-2023-53201: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound of the…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: wraparound mbox producer index
Driver is not handling the wraparound of the mbox producer index correctly.
Currently the wraparound happens once u32 max is reached.
Bit 31 of the producer index register is special and should be set
only once for the first command. Because the producer index overflow
setting bit31 after a long time, FW goes to initialization sequence
and this causes FW hang.
Fix is to wraparound the mbox producer index once it reaches u16 max.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 < 9341501e2f7af29f5b5562c2840a7fde40eb7de4 | 9341501e2f7af29f5b5562c2840a7fde40eb7de4 |
| linux | linux | >= 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 < 79226176cdd1b65a1e6a90e0e1a2b490f0a9df33 | 79226176cdd1b65a1e6a90e0e1a2b490f0a9df33 |
| linux | linux | >= 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 < c9be352be9bb15e6b83e40abc4df7f4776b435ba | c9be352be9bb15e6b83e40abc4df7f4776b435ba |
| linux | linux | >= 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 < 7bfa0303fbc265c94cfbd17505c55b99848aa4e3 | 7bfa0303fbc265c94cfbd17505c55b99848aa4e3 |
| linux | linux | >= 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 < 50d77c3739b2b15e9e1f1c9cbe50037d294800f8 | 50d77c3739b2b15e9e1f1c9cbe50037d294800f8 |
| linux | linux | >= 1ac5a404797523cedaf424a3aaa3cf8f9548dff8 < 0af91306e17ef3d18e5f100aa58aa787869118af | 0af91306e17ef3d18e5f100aa58aa787869118af |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 4.11 < 5.10.188 | 5.10.188 |
| linux | linux_kernel | >= 5.11 < 5.15.121 | 5.15.121 |
| linux | linux_kernel | >= 5.16 < 6.1.39 | 6.1.39 |
| linux | linux_kernel | >= 6.2 < 6.3.13 | 6.3.13 |
| linux | linux_kernel | >= 6.4 < 6.4.4 | 6.4.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53201: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound
osv·2025-09-15·CVSS 5.5
CVE-2023-53201 [MEDIUM] CVE-2023-53201: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound of the mbox producer index correctly. Currently the wraparound happens once u32 max is reached. Bit 31 of the producer index register is special and should be set only once for the first command. Because the producer index overflow setting bit31 after a long time, FW goes to initialization sequence and this causes FW hang. Fix is to wraparound the mbox producer index once it reaches u16 max.
GHSA
GHSA-p8h3-xc7h-q8r7: In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: wraparound mbox producer index
Driver is not handling the wraparou
ghsa_unreviewed·2025-09-15
CVE-2023-53201 [MEDIUM] GHSA-p8h3-xc7h-q8r7: In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: wraparound mbox producer index
Driver is not handling the wraparou
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: wraparound mbox producer index
Driver is not handling the wraparound of the mbox producer index correctly.
Currently the wraparound happens once u32 max is reached.
Bit 31 of the producer index register is special and should be set
only once for the first command. Because the producer index overflow
setting bit31 after a long time, FW goes to initialization sequence
and this causes FW hang.
Fix is to wraparound the mbox producer index once it reaches u16 max.
Red Hat
kernel: RDMA/bnxt_re: wraparound mbox producer index
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2023-53201 [MEDIUM] CWE-682 kernel: RDMA/bnxt_re: wraparound mbox producer index
kernel: RDMA/bnxt_re: wraparound mbox producer index
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: wraparound mbox producer index
Driver is not handling the wraparound of the mbox producer index correctly.
Currently the wraparound happens once u32 max is reached.
Bit 31 of the producer index register is special and should be set
only once for the first command. Because the producer index overflow
setting bit31 after a long time, FW goes to initialization sequence
and this causes FW hang.
Fix is to wraparound the mbox producer index once it reaches u16 max.
Statement: The issue in the Broadcom bnxt_re RDMA driver was caused by incorrect handling of the mailbox producer index wraparound, which could eventually trigger firmware reinitialization.
This resu
Debian
CVE-2023-53201: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_r...
vendor_debian·2023·CVSS 5.5
CVE-2023-53201 [MEDIUM] CVE-2023-53201: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_r...
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: wraparound mbox producer index Driver is not handling the wraparound of the mbox producer index correctly. Currently the wraparound happens once u32 max is reached. Bit 31 of the producer index register is special and should be set only once for the first command. Because the producer index overflow setting bit31 after a long time, FW goes to initialization sequence and this causes FW hang. Fix is to wraparound the mbox producer index once it reaches u16 max.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.4.4-1)
sid: resolved (fixed in 6.4.4-1)
trixie: resolved (fixed in 6.4.4-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0af91306e17ef3d18e5f100aa58aa787869118afhttps://git.kernel.org/stable/c/50d77c3739b2b15e9e1f1c9cbe50037d294800f8https://git.kernel.org/stable/c/79226176cdd1b65a1e6a90e0e1a2b490f0a9df33https://git.kernel.org/stable/c/7bfa0303fbc265c94cfbd17505c55b99848aa4e3https://git.kernel.org/stable/c/9341501e2f7af29f5b5562c2840a7fde40eb7de4https://git.kernel.org/stable/c/c9be352be9bb15e6b83e40abc4df7f4776b435ba
2025-09-15
Published