CVE-2023-53729
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53729 is a vulnerability discovered in the Linux kernel's Qualcomm Messaging Interface (QMI) string decoder component, disclosed on October 22, 2025. The vulnerability affects the soc:qcom:qmi_encdec module, specifically in how it handles string length in the decode function (Red Hat CVE, NVD).

Technical details

The vulnerability occurs when the QMI TLV value for strings in qmi element info structures accounts for null-terminated strings with MAXLEN + 1. If a string's length equals MAXLEN + 1, it causes an out-of-bounds access when the NULL character is appended during decoding. The vulnerability has been assigned a CVSS v3.1 base score of 6.6 with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H and is classified as CWE-787 (Red Hat CVE).

Impact

The vulnerability could lead to kernel memory corruption and potential denial-of-service if malformed QMI messages are processed, for example through a compromised modem or firmware-controlled interface. This could affect system stability and potentially lead to system crashes (Red Hat CVE).

Mitigation and workarounds

Multiple Linux distributions have released patches to address this vulnerability. Ubuntu has released fixes for various kernel versions including 5.15.0-94.104 for 22.04 LTS and 5.4.0-169.187 for 20.04 LTS. Red Hat has deferred fixes for Enterprise Linux 8 and 9, while versions 6 and 7 are not affected (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-riscv
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-azure-5.4
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-debug-uki-virt-addons
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • rtla
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management