CVE-2023-53148
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53148 is a vulnerability in the Linux kernel affecting the Intel Gigabit Ethernet (igb) driver. The issue was discovered and disclosed on September 15, 2025, affecting systems where a Thunderbolt hub connects to Ethernet and a display through USB Type-C (NVD).

Technical details

The vulnerability occurs when the igb_down function is called multiple times during a Thunderbolt hub unplug event. Specifically, the first call is triggered by igb_io_error_detected and the second by igb_remove. The second call to igb_down blocks at napi_synchronize, causing a hung task timeout. In this scenario, igb_io_error_detected detaches the network interface and requests a PCIE slot reset, but the PCIE reset callback is not invoked, resulting in the Ethernet connection breaking down (NVD).

Impact

When exploited, this vulnerability causes a system hang when users remove the cable between the PC and the Thunderbolt hub, leading to potential system unresponsiveness and disruption of network connectivity (NVD).

Mitigation and workarounds

The issue has been fixed in various Linux distributions including Ubuntu 22.04 LTS (jammy), 20.04 LTS (focal), and other versions. The fix involves modifying the driver to ignore non-fatal PCIE errors, as requesting a slot reset is unnecessary in this case. This preserves the Ethernet connection and prevents the task hung issue (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-core
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • rv
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management