
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53382 is a vulnerability identified in the Linux kernel, specifically affecting the net/smc component. The vulnerability was discovered when using SMCRv2 with Mellanox ConnectX-4 hardware, causing system crashes during CLC handshake operations (NVD).
The vulnerability manifests during the CLC handshake process where the server sequentially tries available SMCRv2 and SMCRv1 devices in smclistenwork(). When an SMCRv2 device is found and SMCv2 based link group and link are assigned to the connection, subsequent buffer assignment errors can occur. If the server then attempts to fall back to SMCRv1, the previously assigned SMCRv2 resources aren't properly reset, leading to a NULL pointer dereference when accessing conn->rmbdesc->mr[link->linkidx] (NVD).
The vulnerability results in a kernel NULL pointer dereference, which can cause system crashes. This can be triggered during high-load scenarios, such as when running nginx with multiple concurrent connections, potentially leading to denial of service conditions (NVD).
The vulnerability has been resolved by implementing a fix that cleans conn->lnk before assigning a link and resets the connection when trying SMCRv2 fails in buffer creation or registration (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."