CVE-2023-54133
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54133 is a resource leak vulnerability in the Linux kernel's NFP (Netronome Flow Processor) network driver. When a network device is moved between namespaces, multicast (MC) addresses are cleaned in software but not removed from the application firmware, causing them to persist and leak resources. The vulnerability was published on December 24, 2025, and affects Linux kernel versions starting from 6.2 up to (but not including) the patched commits in the 6.4.5 and 6.5 stable releases. The CVSS estimate is Medium severity with an EPSS score of 0.000180 (Feedly, EUVD).

Technical details

The root cause is improper resource cleanup (CWE-400: Uncontrolled Resource Consumption) in the NFP driver's port-closing logic. When a network interface using the NFP driver is moved from one Linux network namespace to another, the kernel cleans multicast addresses in its software state but fails to call the corresponding firmware-level cleanup, leaving stale MC address entries in the application firmware. The fix introduces a call to __dev_mc_unsync during port close to synchronize and remove multicast addresses from the firmware, preventing the leak (Feedly, Linux Kernel Git).

Impact

The primary impact is a resource leak within the NFP network driver's firmware state, which can degrade the availability and stability of affected network interfaces over time. Repeated namespace migrations of NFP-backed devices could exhaust firmware multicast address table entries, potentially causing network functionality degradation or denial of service on systems using Netronome NFP hardware. There is no known confidentiality or integrity impact, and the vulnerability does not enable remote code execution or privilege escalation (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have addressed this vulnerability in stable releases 6.4.5 and 6.5 via commits c427221733d49fd1e1b79b4a86746acf3ef660e7 and cc7eab25b1cf3f9594fe61142d3523ce4d14a788. Users running affected kernel versions (6.2 through pre-6.4.5/6.5) on systems with Netronome NFP hardware should upgrade to a patched kernel version. As a workaround, avoiding namespace migration of NFP-backed network devices can prevent the resource leak from occurring (Linux Kernel Git, Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management