cbcvebase.
CVE-2023-52530
published 2024-03-02

CVE-2023-52530: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential key use-after-free When ieee80211_key_link() is called by…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential key use-after-free When ieee80211_key_link() is called by ieee80211_gtk_rekey_add() but returns 0 due to KRACK protection (identical key reinstall), ieee80211_gtk_rekey_add() will still return a pointer into the key, in a potential use-after-free. This normally doesn't happen since it's only called by iwlwifi in case of WoWLAN rekey offload which has its own KRACK protection, but still better to fix, do that by returning an error code and converting that to success on the cfg80211 boundary only, leaving the error for bad callers of ieee80211_gtk_rekey_add().

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.64-1 (bookworm)linux 6.1.64-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.50 < 3.173.17
linuxlinux>= 3.18.82 < 3.193.19
linuxlinux>= 3.2.95 < 3.33.3
linuxlinux>= 4.1.47 < 4.24.2
linuxlinux>= 4.13.14 < 4.144.14
linuxlinux>= 4.4.99 < 4.54.5
linuxlinux>= 4.9.63 < 4.104.10
linuxlinux>= fdf7cb4185b60c68e1a75e61691c4afdc15dea0e < 2408f491ff998d674707725eadc47d8930aced092408f491ff998d674707725eadc47d8930aced09
linuxlinux>= fdf7cb4185b60c68e1a75e61691c4afdc15dea0e < e8e599a635066c50ac214c3e10858f1d37e03022e8e599a635066c50ac214c3e10858f1d37e03022
linuxlinux>= fdf7cb4185b60c68e1a75e61691c4afdc15dea0e < e8a834eb09bb95c2bf9c76f1a28ecef7d8c439d0e8a834eb09bb95c2bf9c76f1a28ecef7d8c439d0
linuxlinux>= fdf7cb4185b60c68e1a75e61691c4afdc15dea0e < 2f4e16e39e4f5e78248dd9e51276a83203950b362f4e16e39e4f5e78248dd9e51276a83203950b36
linuxlinux>= fdf7cb4185b60c68e1a75e61691c4afdc15dea0e < 65c72a7201704574dace708cbc96a8f367b1491d65c72a7201704574dace708cbc96a8f367b1491d
linuxlinux>= fdf7cb4185b60c68e1a75e61691c4afdc15dea0e < 31db78a4923ef5e2008f2eed321811ca79e7f71b31db78a4923ef5e2008f2eed321811ca79e7f71b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.64-16.1.64-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.