nvme-tcp: don't access released socket during error recovery
Published Oct 7, 2025
7.8
HIGHCVSS 3.1
EPSS 0.16%
Description
While the error recovery work is temporarily failing reconnect attempts, running the 'nvme list' command causes a kernel NULL pointer dereference by calling getsockname() with a released socket.
During error recovery work, the nvme tcp socket is released and a new one created, so it is not safe to access the socket without proper check.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.1StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.1
- Version 6.1.18StatusunaffectedConstraints<=6.1.*
- Version 6.2.5StatusunaffectedConstraints<=6.2.*
- Version 6.3StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.1 · < 6.1.18
- ≥ 6.2 · < 6.2.5
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The issue arises because of insufficient synchronization between error recovery operations and socket information queries. When an NVMe-over-TCP connection experiences errors, the error recovery work releases the existing socket and creates a new one to establish a fresh connection. During this transition, there is a window where the socket pointer may be NULL or point to freed memory. If userspace executes the 'nvme list' command during this window, the kernel attempts to gather connection information by calling getsockname() on the socket. Without proper validation, this results in dereferencing a NULL or invalid pointer, causing an immediate kernel crash. The race window is narrow, requiring error recovery to be actively cycling sockets when the list command executes. While this reliably causes crashes when the race is won, NULL pointer dereferences on modern kernels with SMAP/SMEP protections cannot be exploited for code execution or information disclosure, only denial of service.
Red Hat mitigation
To mitigate this issue, prevent the nvme_tcp module from loading. See https://access.redhat.com/solutions/41278 for instructions on blacklisting kernel modules.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2 other sources (CVE.org, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.16% (0.00162) | 4.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.14% (0.00140) | 3.65th | v5 (v2026.06.15) |
| Oct 8, 2025 | 0.02% (0.00017) | 2.79th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2023-53643 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2402186 Issue Tracking
- https://git.kernel.org/stable/c/76d54bf20cdcc1ed7569a89885e09636e9a8d71d Patch
- https://git.kernel.org/stable/c/d82f762db4776fa11de88018f0f5de2d5db72a72 Patch
- https://git.kernel.org/stable/c/fe2d9e54165dadaa0d0cc3355c0be9c3e129fa0d Patch
- https://lore.kernel.org/linux-cve-announce/2025100716-CVE-2023-53643-4725@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53643
- https://www.cve.org/CVERecord?id=CVE-2023-53643
Change history (0)
No recorded changes yet.