
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-54219 is a vulnerability in the Linux kernel related to the IB/isert (iSCSI Extensions for RDMA) subsystem, specifically a revert of commit 699826f4e30a ("IB/isert: Fix incorrect release of isert connection") that was causing kernel warnings and instability during DEVICE_REMOVAL events on OPA (Omni-Path Architecture) hardware. The issue manifests as a kernel WARNING in ib_cq_pool_cleanup (at drivers/infiniband/core/cq.c:359) when the hfi1 module is removed during active iSCSI/RDMA connections. It was published on December 30, 2025, and affects multiple stable Linux kernel versions. The CVSS category is estimated as Medium (Feedly).
The root cause is an incorrect connection release sequence in the ib_isert driver introduced by commit 699826f4e30a. When a DEVICE_REMOVAL event occurs on OPA hardware, the flawed release logic triggers a kernel WARNING in ib_cq_pool_cleanup, indicating that completion queues are not properly cleaned up before the InfiniBand core module attempts to finalize them. This is classified as a use-after-free or improper resource cleanup issue (CWE-459: Incomplete Cleanup). The fix is a revert of the offending commit, restoring the prior connection release behavior. The vulnerability requires local access and specific hardware (OPA/hfi1) with active iSCSI over RDMA (iSER) connections to trigger (Feedly).
Exploitation of this vulnerability results in a kernel WARNING and potential system instability or crash (denial of service) during DEVICE_REMOVAL events on systems using OPA (Omni-Path Architecture) InfiniBand hardware with the ib_isert and hfi1 drivers loaded. There is no evidence of confidentiality or integrity impact; the primary risk is availability, as the kernel warning can disrupt iSCSI/RDMA storage connectivity and potentially destabilize the host during hardware removal operations (Feedly).
The fix is a revert of commit 699826f4e30a applied across multiple stable kernel branches, with patches available at the following kernel.org stable commits: 1bb42aca7a96, 3f39698e7e84, 9b6296861a5a, 77e90bd53019, and 4082b59705ee. Users should update to a patched Linux kernel version that includes these fixes. As a workaround, avoiding hot-removal of OPA/hfi1 devices while iSER connections are active can reduce the risk of triggering the WARNING (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."