CVE-2023-53340
net/mlx5: Collect command failures data only for known commands
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Collect command failures data only for known commands DEVX can issue a general command, which is not used by mlx5 driver. In case such command is failed, mlx5 is trying to collect the failure data, However, mlx5 doesn't create a storage for this command, since mlx5 doesn't use it. This lead to array-index-out-of-bounds error. Fix it by checking whether the command is known before collecting the failure data.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Sep 17, 2025 |
| Last Updated | May 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new high vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
34f46ae0d4b38e83cfb26fb6f06b5b5efea47fdc < 411e4d6caa7f7169192b8dacc8421ac4fd64a354 34f46ae0d4b38e83cfb26fb6f06b5b5efea47fdc < d8b6f175235d7327b4e1b13216859e89496dfbd5 34f46ae0d4b38e83cfb26fb6f06b5b5efea47fdc < 2a0a935fb64ee8af253b9c6133bb6702fb152ac2
Linux / Linux
5.18