CVE-2023-53383: irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4

Published Sep 18, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4

The T241 platform suffers from the T241-FABRIC-4 erratum which causes unexpected behavior in the GIC when multiple transactions are received simultaneously from different sources. This hardware issue impacts NVIDIA server platforms that use more than two T241 chips interconnected. Each chip has support for 320 {E}SPIs.

This issue occurs when multiple packets from different GICs are incorrectly interleaved at the target chip. The erratum text below specifies exactly what can cause multiple transfer packets susceptible to interleaving and GIC state corruption. GIC state corruption can lead to a range of problems, including kernel panics, and unexpected behavior.

From the erratum text: "In some cases, inter-socket AXI4 Stream packets with multiple transfers, may be interleaved by the fabric when presented to ARM Generic Interrupt Controller. GIC expects all transfers of a packet to be delivered without any interleaving.

The following GICv3 commands may result in multiple transfer packets over inter-socket AXI4 Stream interface: - Register reads from GICDI and GICDN - Register writes to 64-bit GICD registers other than GICDIROUTERn - ITS command MOVALL

Multiple commands in GICv4+ utilize multiple transfer packets, including VMOVP, VMOVI, VMAPP, and 64-bit register accesses."

This issue impacts system configurations with more than 2 sockets, that require multi-transfer packets to be sent over inter-socket AXI4 Stream interface between GIC instances on different sockets. GICv4 cannot be supported. GICv3 SW model can only be supported with the workaround. Single and Dual socket configurations are not impacted by this issue and support GICv3 and GICv4."

Writing to the chip alias region of the GICDIn{E} registers except GICDICENABLERn has an equivalent effect as writing to the global distributor. The SPI interrupt deactivate path is not impacted by the erratum.

To fix this problem, implement a workaround that ensures read accesses to the GICDIn{E} registers are directed to the chip that owns the SPI, and disable GICv4.x features. To simplify code changes, the gicconfigureirq() function uses the same alias region for both read and write operations to GICDICFGR.

Affected Software

4 affected components
Nvidia Linux Kernel
Microsoft cbl2 kernel 5.15.186.1-1
Linux Linux kernel<6.1.30
Linux Linux kernel>=6.2<6.3.4

Event History

Sep 18, 2025
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityAffected Software
Dec 13, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-53383?

The severity of CVE-2023-53383 is classified as moderate, due to the risk of unexpected behavior in the GIC.

2

How do I fix CVE-2023-53383?

To fix CVE-2023-53383, apply the latest patches for the Linux Kernel provided by NVIDIA that address the T241-FABRIC-4 erratum.

3

What systems are affected by CVE-2023-53383?

CVE-2023-53383 affects systems utilizing the NVIDIA Linux Kernel on the T241 platform.

4

What happens if I do not address CVE-2023-53383?

If CVE-2023-53383 is not addressed, the system may experience unexpected behaviors, especially under conditions of simultaneous transactions.

5

Is there a workaround for CVE-2023-53383?

Yes, a workaround has been implemented in the Linux Kernel to mitigate the effects of the T241-FABRIC-4 erratum associated with CVE-2023-53383.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203