CVE-2023-53273: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Drivers: vmbus: Check for channel allocation before looking up relids relid2channel() assumes vmbus channel array to be allocated when called. However, in cases such as kdump/kexec, not all relids will be reset by the host. When the second kernel boots and if the guest receives a vmbus interrupt during vmbus driver initialization before vmbus_connect() is called, before it finishes, or if it fails, the vmbus interrupt service routine is called which in turn calls relid2channel() and can cause a null pointer dereference. Print a warning and error out in relid2channel() for a channel id that's invalid in the second kernel.

Affected products

  • Linux Linux Kernel: from 5.8, before 5.10.178 (fixed in 5.10.178); from 5.11, before 5.15.107 (fixed in 5.15.107); from 5.16, before 6.1.24 (fixed in 6.1.24); from 6.2, before 6.2.11 (fixed in 6.2.11); version 6.3 only

Published 2025-09-16. Last modified 2026-06-17.