Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — virtio_net: Fix error unwinding of XDP initialization
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N N H 5.5 .0015 4.4 —
AFFECTED
Product Versions Fixed
Linux 754b8a21a96d5f11712245aef907149606b323ae – —
Linux 4.16 – 5.15.113
TIMELINE
Oct 1 Reserved by Linux
Oct 1 Published (CNA: Linux)
Aug 4 RESCORED — CVE-2023-53499 (Linux). CVSS 7 → 5.5 (NVD).
Description
In the Linux kernel, the following vulnerability has been resolved:
virtio_net: Fix error unwinding of XDP initialization
When initializing XDP in virtnet_open(), some rq xdp initialization
may hit an error causing net device open failed. However, previous
rqs have already initialized XDP and enabled NAPI, which is not the
expected behavior. Need to roll back the previous rq initialization
to avoid leaks in error unwinding of init code.
Also extract helper functions of disable and enable queue pairs.
Use newly introduced disable helper function in error unwinding and
virtnet_close. Use enable helper function in virtnet_open.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| October 1, 2025 | Reserved | Reserved by Linux |
| October 1, 2025 | Published | Published (CNA: Linux) |
| August 4, 2026 | RESCORED | RESCORED — CVE-2023-53499 (Linux). CVSS 7 → 5.5 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 754b8a21a96d5f11712245aef907149606b323ae | — |
| Linux | Linux | — | 4.16 | 5.15.113 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-53499 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.