Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2023-53591

5.5 · MEDIUM
Published Oct 4, 2025 linux CWE-667 EPSS 0.12% (2th pctl)

Overview

CVE-2023-53591 is a medium-severity vulnerability affecting linux linux_kernel. It was published on October 4, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix deadlock in tc route query code

Cited commit causes ABBA deadlock[0] when peer flows are created while

holding the devcom rw semaphore. Due to peer flows offload implementation

the lock is taken much higher up the call chain and there is no obvious way

to easily fix the deadlock. Instead, since tc route query code needs the

peer eswitch structure only to perform a lookup in xarray and doesn't

perform any sleeping operations with it, refactor the code for lockless

execution in following ways:

- RCUify the devcom 'data' pointer. When resetting the pointer

synchronously wait for RCU grace period before returning. This is fine

since devcom is currently only used for synchronization of

pairing/unpairing of eswitches which is rare and already expensive as-is.

- Wrap all usages of 'paired' boolean in {READ|WRITE}_ONCE(). The flag has

already been used in some unlocked contexts without proper

annotations (e.

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.13.17, < 5.14 Affected

Frequently Asked Questions

What is CVE-2023-53591?

CVE-2023-53591 is a medium-severity vulnerability affecting linux linux_kernel. It was published on October 4, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2023-53591?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2023-53591?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2023-53591?

CyberStrike's AI-powered security agents can automatically detect CVE-2023-53591 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.