CVE-2023-52688
published 2024-05-17CVE-2023-52688: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config throws…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix the error handler of rfkill config
When the core rfkill config throws error, it should free the
allocated resources. Currently it is not freeing the core pdev
create resources. Avoid this issue by calling the core pdev
destroy in the error handler of core rfkill config.
Found this issue in the code review and it is compile tested only.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.7.7-1 (forky) | linux 6.7.7-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 004ccbc0dd49c63576a4c60a663a38dd3cb6bee5 < b4e593a7a22fa3c7d0550ef51c90b5c21f790aa8 | b4e593a7a22fa3c7d0550ef51c90b5c21f790aa8 |
| linux | linux | >= 004ccbc0dd49c63576a4c60a663a38dd3cb6bee5 < 898d8b3e1414cd900492ee6a0b582f8095ba4a1a | 898d8b3e1414cd900492ee6a0b582f8095ba4a1a |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 0 < 6.7.7-1 | 6.7.7-1 |
| linux | linux_kernel | >= 6.7 < 6.7.2 | 6.7.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.6/6.7/6.7.1 ath12k allocation of resources (b4e593a7a22f/898d8b3e1414 / Nessus ID 246694)
vuldb·2026-07-12·CVSS 7.8
CVE-2023-52688 [HIGH] Linux Kernel up to 6.6/6.7/6.7.1 ath12k allocation of resources (b4e593a7a22f/898d8b3e1414 / Nessus ID 246694)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6/6.7/6.7.1. Affected is an unknown function of the component ath12k. Such manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2023-52688. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
OSV
CVE-2023-52688: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config t
osv·2024-05-17·CVSS 7.8
CVE-2023-52688 [HIGH] CVE-2023-52688: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config t
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config throws error, it should free the allocated resources. Currently it is not freeing the core pdev create resources. Avoid this issue by calling the core pdev destroy in the error handler of core rfkill config. Found this issue in the code review and it is compile tested only.
GHSA
GHSA-6rhx-7f5j-52mj: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix the error handler of rfkill config
When the core rfkill config
ghsa_unreviewed·2024-05-17
CVE-2023-52688 [HIGH] CWE-415 GHSA-6rhx-7f5j-52mj: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix the error handler of rfkill config
When the core rfkill config
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix the error handler of rfkill config
When the core rfkill config throws error, it should free the
allocated resources. Currently it is not freeing the core pdev
create resources. Avoid this issue by calling the core pdev
destroy in the error handler of core rfkill config.
Found this issue in the code review and it is compile tested only.
Red Hat
kernel: wifi: ath12k: fix the error handler of rfkill config
vendor_redhat·2024-05-17·CVSS 7.8
CVE-2023-52688 [HIGH] kernel: wifi: ath12k: fix the error handler of rfkill config
kernel: wifi: ath12k: fix the error handler of rfkill config
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix the error handler of rfkill config
When the core rfkill config throws error, it should free the
allocated resources. Currently it is not freeing the core pdev
create resources. Avoid this issue by calling the core pdev
destroy in the error handler of core rfkill config.
Found this issue in the code review and it is compile tested only.
A vulnerability was found in the ath12k Wi-Fi driver within the Linux kernel. This issue involves an error handler issue in the rfkill configuration, which could potentially disrupt Wi-Fi functionality and error handling processes.
Statement: Red Hat Enterprise Linux is not vulnerable to this CVE, as it does no
Debian
CVE-2023-52688: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath12...
vendor_debian·2023·CVSS 7.8
CVE-2023-52688 [HIGH] CVE-2023-52688: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath12...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config throws error, it should free the allocated resources. Currently it is not freeing the core pdev create resources. Avoid this issue by calling the core pdev destroy in the error handler of core rfkill config. Found this issue in the code review and it is compile tested only.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.7.7-1)
sid: resolved (fixed in 6.7.7-1)
trixie: resolved (fixed in 6.7.7-1)
No detection rules found.
No public exploits indexed.
2024-05-17
Published