
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53528 is a vulnerability discovered in the Linux kernel's RDMA/rxe component, disclosed on October 1, 2025. The vulnerability affects the queue pair (qp) cleanup code in the RDMA/rxe subsystem. When create_qp does not fully succeed, there is a potential for the cleanup code to attempt draining send or recv work queues before they are created (NVD, Ubuntu).
The vulnerability occurs in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem, specifically in the RXE (RDMA over Ethernet) component. The issue manifests when the queue pair creation process fails partially, leading to an unsafe attempt to drain work queues that haven't been properly initialized. This can result in a segmentation fault due to accessing non-existent queues (RedHat).
The vulnerability can lead to a segmentation fault in the Linux kernel when specific conditions are met during RDMA queue pair cleanup operations. This could potentially affect system stability and cause service disruptions (NVD).
A fix has been implemented that adds checks to verify the existence of queues before attempting to drain them. The patch ensures that the code validates whether the queues exist before performing drain operations (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."