Answer in brief
CVE-2023-53110 records a High severity (CVSS 7.5) vulnerability in net/smc: fix NULL sndbuf_desc in smc_cdc_tx_handler(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0b29ec6436138721acf5844e558f7334a0fa61d5 <31817c530768b0199771ec6019571b4f0ddbf230 || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <b108bd9e6be000492ebebe867daa699285978a10 || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <3c270435db8aa34929263dddae8fd050f5216ecb || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <3ebac7cf0a184a8102821a7a00203f02bebda83c || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <22a825c541d775c1dbe7b2402786025acad6727b | 31817c530768b0199771ec6019571b4f0ddbf230, b108bd9e6be000492ebebe867daa699285978a10, 3c270435db8aa34929263dddae8fd050f5216ecb, 3ebac7cf0a184a8102821a7a00203f02bebda83c, 22a825c541d775c1dbe7b2402786025acad6727b |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
May 2, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL sndbuf_desc in smc_cdc_tx_handler() When performing a stress test on SMC-R by rmmod mlx5_ib driver during the wrk/nginx test, we found that there is a probability of triggering a panic while terminating all link groups. This issue dues to the race between smc_smcr_terminate_all() and smc_buf_create(). smc_smcr_terminate_all smc_buf_create /* init */ conn->sndbuf_desc = NULL; ... __smc_lgr_terminate smc_conn_kill smc_close_abort smc_cdc_get_slot_and_msg_send __softirqentry_text_start smc_wr_tx_process_cqe smc_cdc_tx_handler READ(conn->sndbuf_desc->len); /* panic dues to NULL sndbuf_desc */ conn->sndbuf_desc = xxx; This patch tries to fix the issue by always to check the sndbuf_desc before send any cdc msg, to make sure that no null pointer is seen during cqe processing.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2023-53110 records a High severity (CVSS 7.5) vulnerability in net/smc: fix NULL sndbuf_desc in smc_cdc_tx_handler(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0b29ec6436138721acf5844e558f7334a0fa61d5 <31817c530768b0199771ec6019571b4f0ddbf230 || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <b108bd9e6be000492ebebe867daa699285978a10 || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <3c270435db8aa34929263dddae8fd050f5216ecb || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <3ebac7cf0a184a8102821a7a00203f02bebda83c || >=0b29ec6436138721acf5844e558f7334a0fa61d5 <22a825c541d775c1dbe7b2402786025acad6727b | 31817c530768b0199771ec6019571b4f0ddbf230, b108bd9e6be000492ebebe867daa699285978a10, 3c270435db8aa34929263dddae8fd050f5216ecb, 3ebac7cf0a184a8102821a7a00203f02bebda83c, 22a825c541d775c1dbe7b2402786025acad6727b |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
May 2, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL sndbuf_desc in smc_cdc_tx_handler() When performing a stress test on SMC-R by rmmod mlx5_ib driver during the wrk/nginx test, we found that there is a probability of triggering a panic while terminating all link groups. This issue dues to the race between smc_smcr_terminate_all() and smc_buf_create(). smc_smcr_terminate_all smc_buf_create /* init */ conn->sndbuf_desc = NULL; ... __smc_lgr_terminate smc_conn_kill smc_close_abort smc_cdc_get_slot_and_msg_send __softirqentry_text_start smc_wr_tx_process_cqe smc_cdc_tx_handler READ(conn->sndbuf_desc->len); /* panic dues to NULL sndbuf_desc */ conn->sndbuf_desc = xxx; This patch tries to fix the issue by always to check the sndbuf_desc before send any cdc msg, to make sure that no null pointer is seen during cqe processing.
Quoted source text, attributed separately from HOL analysis.