CVE-2023-53657

Advisory lineage Upstream: 0 Downstream: 16
Analyzed
Published: 07 Oct 2025, 15:21
Last modified:11 May 2026, 19:49

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.01% LOW
0% probability -0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Oct 2025, 15:21
Published
Vulnerability first disclosed
11 May 2026, 19:49
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: ice: Don't tx before switchdev is fully configured There is possibility that ice_eswitch_port_start_xmit might be called while some resources are still not allocated which might cause NULL pointer dereference. Fix this by checking if switchdev configuration was finished.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.01% Percentile: 2%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ f5396b8a663f7a78ee5b75a47ee524b40795b265, < 5760a72b3060150b587eff3e879648c7470efddd | ≥ f5396b8a663f7a78ee5b75a47ee524b40795b265, < 63ff5a94649837d980e3b9ef535c793ec8cb0ca7 | ≥ f5396b8a663f7a78ee5b75a47ee524b40795b265, < 7aa529a69e92b9aff585e569d5003f7c15d8d60b | 5.16

  • linuxlinux_kernel

    ≥ 5.16, < 6.1.55 | ≥ 6.2, < 6.5.5

References (3)