CVE-2023-53322
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53322 is a use-after-free (UAF) vulnerability in the Linux kernel's SCSI qla2xxx driver, specifically in the terminate_rport_io function. The flaw allows the function to exit before ensuring all in-flight I/Os have returned, leaving the driver holding references to already-freed resources and causing a system crash. It affects multiple Linux kernel stable branches: versions before 4.14.322, 4.15–4.19.291, 4.20–5.4.251, 5.5–5.10.188, 5.11–5.15.121, 5.16–6.1.40, and 6.2–6.4.5. The vulnerability was published on September 16, 2025, and carries a CVSS v3.1 base score of 7.8 (High) (Red Hat CVE, Feedly).

Technical details

The root cause is a race condition in the terminate_rport_io callback of the qla2xxx Fibre Channel HBA driver (CWE-416: Use After Free). For FCP-2 devices, I/Os can remain pending in hardware because the driver does not tear down the firmware session at the first sign of a cable pull. When the dev_loss_tmo timer fires, terminate_rport_io is called and the upper SCSI layer begins freeing resources; however, the qla2xxx cleanup path may not complete in time, leaving the driver accessing already-freed memory. The fix ensures the driver waits for all I/Os to return to the upper layer before resources are released (Red Hat CVE, kernel.org patches). Exploitation requires local access with low privileges (PR:L), and no network exposure is involved.

Impact

Successful exploitation can cause a kernel panic (system crash), resulting in a complete loss of availability for the affected host. Because the vulnerability involves accessing freed kernel memory, there is also a theoretical risk of arbitrary kernel code execution, which could compromise confidentiality and integrity of all data on the system. The scope is limited to the local machine running a vulnerable kernel with the qla2xxx driver active, but a kernel-level compromise could enable full privilege escalation and lateral movement within an environment (Red Hat CVE, Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.024% (0.000240), indicating a very low probability of exploitation in the near term. The local attack vector and requirement for low-privilege access further limit the practical exploitability of this flaw.

Mitigation and workarounds

The primary remediation is to update to a patched Linux kernel version. Fixed versions are available across all affected stable branches: 4.14.322, 4.19.291, 5.4.251, 5.10.188, 5.15.121, 6.1.40, 6.4.5, and 6.5 (Red Hat CVE, Feedly). Red Hat has issued errata (e.g., RHSA-2025:22072, RHSA-2025:23422, RHSA-2025:23947, RHSA-2026:0536, RHSA-2026:0643) for affected RHEL versions (Red Hat Errata). SUSE and Oracle Linux have also released corresponding kernel updates. For systems that cannot be immediately patched, consider restricting local user access, disabling the qla2xxx module if Fibre Channel HBAs are not in use, and applying additional kernel hardening controls.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68427MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra
NoYesAug 10, 2026
CVE-2026-68426MEDIUM4.7
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-igx
NoYesAug 10, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 12, 2026
CVE-2026-68430NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-partner
NoYesAug 12, 2026
CVE-2026-68428NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-ibm-6.8
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management