CVE-2023-53382NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: Reset connection when trying to use SMCRv2 fails. We found a crash when using SMCRv2 with 2 Mellanox ConnectX-4. It can be reproduced by: - smc_run nginx - smc_run wrk -t 32 -c 500 -d 30 http://: BUG: kernel NULL pointer dereference, address: 0000000000000014 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 8000000108713067 P4D 8000000108713067 PUD 151127067 PMD 0 Oops: 0000

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.166.1.31+2
Debianlinux/linux_kernel< 6.1.37-1+2
CVEListV5linux/linuxe49300a6bf6218c835403545e9356141a63401819540765d1882d15497d880096de99fafabcfa08c+3
debiandebian/linux< linux 6.1.37-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53382: In the Linux kernel, the following vulnerability has been resolved: net/smc: Reset connection when trying to use SMCRv2 fails2025-09-18
GHSA
GHSA-5322-f7jr-cv4m: In the Linux kernel, the following vulnerability has been resolved: net/smc: Reset connection when trying to use SMCRv2 fails2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: net/smc: Reset connection when trying to use SMCRv2 fails2025-09-18
Debian
CVE-2023-53382: linux - In the Linux kernel, the following vulnerability has been resolved: net/smc: Re...2023
CVE-2023-53382 — NULL Pointer Dereference in Linux | cvebase