Junglewise Threat Intelligence

CVE-2023-53499: Linux kernel virtio_net error unwinding in XDP initialization

CVE-2023-53499 · Severity: high · CVSS 7 · Published 2025-10-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's virtio_net network driver had an incomplete error-handling path when initializing XDP (Express Data Path) receive queues during network device startup. If XDP setup failed on one queue after successfully initializing others, the driver would leave those successfully-initialized queues in an active state with allocated resources, leaking memory and potentially causing system instability. This patch ensures proper cleanup when initialization fails partway through.

Technical details

The vulnerability is an incomplete error unwinding (also called exception handling or rollback) in the virtnet_open() function of the Linux kernel's virtio_net driver. When XDP receive queue registration fails after previous queues have already been initialized and NAPI enabled, the code did not roll back those successful initializations, leaving allocated resources and enabled queue pairs in an inconsistent state. The fix introduces helper functions virtnet_enable_queue_pair() and virtnet_disable_queue_pair() to centralize initialization and cleanup logic, and adds proper error-path code that iterates backwards through initialized queues calling the disable helper. No authentication or network access is required—the issue occurs during normal driver initialization on the local system. The result is resource leaks and potential system instability on network device open failures.

Affected products

  • Linux Linux kernel 5.x and 6.x kernels with virtio_net XDP support

Timeline

  • 2023-05-12: other: Fix authored by Feng Liu
  • 2023-05-15: other: Fix merged upstream by David S. Miller
  • 2023-05-24: other: Fix backported to stable kernel trees

References

Related threats