CVE-2023-54133
published 2025-12-24CVE-2023-54133: In the Linux kernel, the following vulnerability has been resolved: nfp: clean mc addresses in application firmware when closing port When moving devices from…
PriorityP422
EPSS
0.17%
6.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving devices from one namespace to another, mc addresses are
cleaned in software while not removed from application firmware. Thus
the mc addresses are remained and will cause resource leak.
Now use `__dev_mc_unsync` to clean mc addresses when closing port.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.4.11-1 (forky) | linux 6.4.11-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= e20aa071cd955aabc15be0ec1e914283592ddef4 < c427221733d49fd1e1b79b4a86746acf3ef660e7 | c427221733d49fd1e1b79b4a86746acf3ef660e7 |
| linux | linux | >= e20aa071cd955aabc15be0ec1e914283592ddef4 < cc7eab25b1cf3f9594fe61142d3523ce4d14a788 | cc7eab25b1cf3f9594fe61142d3523ce4d14a788 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 0 < 6.4.11-1 | 6.4.11-1 |
| linux | linux_kernel | >= 6.2.0 < 6.4.5 | 6.4.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-54133: In the Linux kernel, the following vulnerability has been resolved: nfp: clean mc addresses in application firmware when closing port When moving devi
osv·2025-12-24
CVE-2023-54133 CVE-2023-54133: In the Linux kernel, the following vulnerability has been resolved: nfp: clean mc addresses in application firmware when closing port When moving devi
In the Linux kernel, the following vulnerability has been resolved: nfp: clean mc addresses in application firmware when closing port When moving devices from one namespace to another, mc addresses are cleaned in software while not removed from application firmware. Thus the mc addresses are remained and will cause resource leak. Now use `__dev_mc_unsync` to clean mc addresses when closing port.
GHSA
GHSA-rhjm-7jhc-x7ww: In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving de
ghsa_unreviewed·2025-12-24
CVE-2023-54133 GHSA-rhjm-7jhc-x7ww: In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving de
In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving devices from one namespace to another, mc addresses are
cleaned in software while not removed from application firmware. Thus
the mc addresses are remained and will cause resource leak.
Now use `__dev_mc_unsync` to clean mc addresses when closing port.
OSV
nfp: clean mc addresses in application firmware when closing port
osv·2025-12-24
CVE-2023-54133 nfp: clean mc addresses in application firmware when closing port
nfp: clean mc addresses in application firmware when closing port
In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving devices from one namespace to another, mc addresses are
cleaned in software while not removed from application firmware. Thus
the mc addresses are remained and will cause resource leak.
Now use `__dev_mc_unsync` to clean mc addresses when closing port.
Red Hat
kernel: nfp: clean mc addresses in application firmware when closing port
vendor_redhat·2025-12-24
CVE-2023-54133 kernel: nfp: clean mc addresses in application firmware when closing port
kernel: nfp: clean mc addresses in application firmware when closing port
In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving devices from one namespace to another, mc addresses are
cleaned in software while not removed from application firmware. Thus
the mc addresses are remained and will cause resource leak.
Now use `__dev_mc_unsync` to clean mc addresses when closing port.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-
Debian
CVE-2023-54133: linux - In the Linux kernel, the following vulnerability has been resolved: nfp: clean ...
vendor_debian·2023
CVE-2023-54133 [LOW] CVE-2023-54133: linux - In the Linux kernel, the following vulnerability has been resolved: nfp: clean ...
In the Linux kernel, the following vulnerability has been resolved: nfp: clean mc addresses in application firmware when closing port When moving devices from one namespace to another, mc addresses are cleaned in software while not removed from application firmware. Thus the mc addresses are remained and will cause resource leak. Now use `__dev_mc_unsync` to clean mc addresses when closing port.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.4.11-1)
sid: resolved (fixed in 6.4.11-1)
trixie: resolved (fixed in 6.4.11-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54133 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54133 CVE-2023-54133 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54133 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving devices from one namespace to another, mc addresses are
cleaned in software while not removed from application firmware. Thus
the mc addresses are remained and will cause resource leak.
__dev_mc_unsync
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dtb-allwinner
dtb-exynos
Sources
NVD
Debian 13
Bugzilla
CVE-2023-54133 kernel: nfp: clean mc addresses in application firmware when closing port
bugzilla·2025-12-24
CVE-2023-54133 CVE-2023-54133 kernel: nfp: clean mc addresses in application firmware when closing port
CVE-2023-54133 kernel: nfp: clean mc addresses in application firmware when closing port
In the Linux kernel, the following vulnerability has been resolved:
nfp: clean mc addresses in application firmware when closing port
When moving devices from one namespace to another, mc addresses are
cleaned in software while not removed from application firmware. Thus
the mc addresses are remained and will cause resource leak.
Now use `__dev_mc_unsync` to clean mc addresses when closing port.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122420-CVE-2023-54133-dc22@gregkh/T
2025-12-24
Published