Review reviewHigh

CVE-2023-54219

Linux

In the Linux kernel, the following vulnerability has been resolved: Revert "IB/isert: Fix incorrect release of isert connection" Commit: 699826f4e30a ("IB/isert: Fix incorrect release of isert connection") is causing problems on OPA when DEVICE_REMOVAL is happening. ------------[ cut here ]------------ WARNING: CPU: 52 PID: 2117247 at drivers/infiniband/core/cq.c:359 ib_cq_pool_cleanup+0xac/0xb0 [ib_core] Modules linked in: nfsd nfs_acl target_core_user uio tcm_fc libfc scsi_transport_fc tcm_loop target_core_pscsi target_core_iblock target_core_file rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_res...

CVSS
7.5
EPSS
0.60%
45.4% percentile
CISA KEV
Not listed
Published
2025.12.30
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.60%
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: Revert "IB/isert: Fix incorrect release of isert connection" Commit: 699826f4e30a ("IB/isert: Fix incorrect release of isert connection") is causing problems on OPA when DEVICE_REMOVAL is happening. ------------[ cut here ]------------ WARNING: CPU: 52 PID: 2117247 at drivers/infiniband/core/cq.c:359 ib_cq_pool_cleanup+0xac/0xb0 [ib_core] Modules linked in: nfsd nfs_acl target_core_user uio tcm_fc libfc scsi_transport_fc tcm_loop target_core_pscsi target_core_iblock target_core_file rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_res...

Affected product and versions

Product
Linux
Affected versions
>= ccf5a1b28e2b73952e8d23126fa1abc6ff99de55 < 77e90bd53019d4d4c9e25552b5efb06dfd8c3c82, >= fb4043077b51e577ecccb3233ecfb8764fcea393 < a277b736309f923d9baff0ef166d694d348a5b96, >= 6718478c18a4f4923d86b81dc7e51363e1a60b03 < 9b6296861a5a9d58aacd72c249a68b073c78bfb4, >= 3c97f2c9ec29ce2f61772f6120aabc852f57132e < aa950b9835f2d004b071fd220459edd3cd0a3603, >= 18512de74454fba6ebd06e579f4f1a3200a9e50d < 1bb42aca7a9611c1991a790834e2a65f3345c5e8, >= 277fbf63b34a377c800d25c7cfd8231ba19cffe2 < 3f39698e7e842abc9bd2bd97bf5eeda4543db758, >= 699826f4e30ab76a62c238c86fbef7e826639c8d < 4082b59705ee9e3912eaa9e15abda8e76039b681, >= 699826f4e30ab76a62c238c86fbef7e826639c8d < a3189341e2f609d48f730b18c8bbbf6783233477, >= 699826f4e30ab76a62c238c86fbef7e826639c8d < dfe261107c080709459c32695847eec96238852b, >= 2f884e6df67347301e51e6be5ad4b61cc8989114, >= 4.14.319 < 4.14.326, >= 4.19.287 < 4.19.295, >= 5.4.248 < 5.4.257, >= 5.10.185 < 5.10.195, >= 5.15.118 < 5.15.132, >= 6.1.35 < 6.1.53, >= 6.3.9 < 6.4, >= 6.4
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
Not available
CVE-2023-54219 — Linux | SECUFOCUS NOW