PT-2025-52985 · Linux+2 · Linux Kernel+2

CVE-2023-54028

·

Published

2025-12-24

·

Updated

2026-08-28

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Linux kernel’s RDMA/rxe component related to the handling of queue pair (QP) cleanup. Specifically, an error can occur when attempting to register a non-static key during the rxe cleanup task() function. This happens if an error occurs before the rxe init task() function is executed, leading to an attempt to access an uninitialized spinlock during the cleanup process. The vulnerable function is rxe create qp(), which calls rxe qp from init() and subsequently rxe init task().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-54028
RHSA-2024:2394
SUSE-SU-2026:0263-1
SUSE-SU-2026:0317-1
SUSE-SU-2026:0411-1
SUSE-SU-2026:0617-1

Affected Products

Debian
Linux Kernel
Red Os