cbcvebase.
CVE-2023-53539
published 2025-10-04

CVE-2023-53539: In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix incomplete state save in rxe_requester If a send packet is dropped by the IP…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix incomplete state save in rxe_requester If a send packet is dropped by the IP layer in rxe_requester() the call to rxe_xmit_packet() can fail with err == -EAGAIN. To recover, the state of the wqe is restored to the state before the packet was sent so it can be resent. However, the routines that save and restore the state miss a significnt part of the variable state in the wqe, the dma struct which is used to process through the sge table. And, the state is not saved before the packet is built which modifies the dma struct. Under heavy stress testing with many QPs on a fast node sending large messages to a slow node dropped packets are observed and the resent packets are corrupted because the dma struct was not restored. This patch fixes this behavior and allows the test cases to succeed.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 3050b99850247695cb07a5c15265afcc08bcf400 < 70518f3aaf5a059b691867d7d2d46b999319656a70518f3aaf5a059b691867d7d2d46b999319656a
linuxlinux>= 3050b99850247695cb07a5c15265afcc08bcf400 < 2f2a6422287fe29f9343247d77b645100ece06522f2a6422287fe29f9343247d77b645100ece0652
linuxlinux>= 3050b99850247695cb07a5c15265afcc08bcf400 < 255c0e60e1d16874fc151358d94bc8df661600dd255c0e60e1d16874fc151358d94bc8df661600dd
linuxlinux>= 3050b99850247695cb07a5c15265afcc08bcf400 < 5d122db2ff80cd2aed4dcd630befb56b51ddf9475d122db2ff80cd2aed4dcd630befb56b51ddf947
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 4.8.1 < 6.1.536.1.53
linuxlinux_kernel>= 6.2 < 6.4.166.4.16
linuxlinux_kernel>= 6.5 < 6.5.36.5.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.