Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — octeon_ep: cancel queued works in probe error path
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0013 3.1 —
AFFECTED
Product Versions Fixed
Linux 24d4333233b378114106a1327d3d635a004f4387 – —
Linux 6.4 – 6.4.12
TIMELINE
Oct 7 Reserved by Linux
Oct 7 Published (CNA: Linux)
Aug 4 RESCORED — CVE-2023-53638 (Linux). CVSS 7 → 7.8 (NVD).
Description
In the Linux kernel, the following vulnerability has been resolved:
octeon_ep: cancel queued works in probe error path
If it fails to get the devices's MAC address, octep_probe exits while
leaving the delayed work intr_poll_task queued. When the work later
runs, it's a use after free.
Move the cancelation of intr_poll_task from octep_remove into
octep_device_cleanup. This does not change anything in the octep_remove
flow, but octep_device_cleanup is called also in the octep_probe error
path, where the cancelation is needed.
Note that the cancelation of ctrl_mbox_task has to follow
intr_poll_task's, because the ctrl_mbox_task may be queued by
intr_poll_task.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| October 7, 2025 | Reserved | Reserved by Linux |
| October 7, 2025 | Published | Published (CNA: Linux) |
| August 4, 2026 | RESCORED | RESCORED — CVE-2023-53638 (Linux). CVSS 7 → 7.8 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 24d4333233b378114106a1327d3d635a004f4387 | — |
| Linux | Linux | — | 6.4 | 6.4.12 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-53638 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.