Junglewise Threat Intelligence

CVE-2023-53504: Linux kernel RDMA bnxt_re use-after-free in device deallocation

CVE-2023-53504 · Severity: high · CVSS 7.8 · Published 2025-10-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA bnxt_re driver for Broadcom network adapters had an incorrect device cleanup sequence that could lead to use-after-free memory corruption. When a device is removed, memory could be accessed after it was freed, potentially allowing a privileged local attacker to crash the system or execute code with kernel privileges.

Technical details

A use-after-free (UAF) vulnerability exists in the RDMA/bnxt_re driver's device removal function due to improper ordering of cleanup operations. The vulnerable code called ib_dealloc_device() before bnxt_re_dev_uninit(), freeing the InfiniBand device structure while references to it still existed during cleanup. An attacker with local access and privileges to trigger device removal or hot-unplug operations could exploit this to cause kernel memory corruption. The fix reorders the cleanup sequence to ensure ib_dealloc_device() is called only after all device-specific cleanup is complete. This is a kernel-level vulnerability requiring local access; no user interaction is needed once device removal is triggered.

Affected products

  • Linux Linux Kernel 5.0 through 6.18 and other stable branches (fixed via commit 5363fc488da579923edf6a2fdca3d3b651dd800b)

Timeline

  • 2023-08-10: disclosed: Patch merged into Linux kernel mainline
  • 2023-08-16: patched: Backported to stable kernel trees

References

Related threats