CVE-2023-52800
published 2024-05-21CVE-2023-52800: In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix htt pktlog locking The ath11k active pdevs are protected by RCU but the…
PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.23%
13.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix htt pktlog locking
The ath11k active pdevs are protected by RCU but the htt pktlog handling
code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a
read-side critical section.
Mark the code in question as an RCU read-side critical section to avoid
any potential use-after-free issues.
Compile tested only.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.64-1 (bookworm) | linux 6.1.64-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d5c65159f2895379e11ca13f62feabe93278985d < 03ed26935bebf6b6fd8a656490bf3dcc71b72679 | 03ed26935bebf6b6fd8a656490bf3dcc71b72679 |
| linux | linux | >= d5c65159f2895379e11ca13f62feabe93278985d < 3a51e6b4da71fdfa43ec006d6abc020f3e22d14e | 3a51e6b4da71fdfa43ec006d6abc020f3e22d14e |
| linux | linux | >= d5c65159f2895379e11ca13f62feabe93278985d < e3199b3fac65c9f103055390b6fd07c5cffa5961 | e3199b3fac65c9f103055390b6fd07c5cffa5961 |
| linux | linux | >= d5c65159f2895379e11ca13f62feabe93278985d < 423762f021825b5e57c3d6f01ff96a9ff19cdcd8 | 423762f021825b5e57c3d6f01ff96a9ff19cdcd8 |
| linux | linux | >= d5c65159f2895379e11ca13f62feabe93278985d < 69cede2a5a5f60e3f5602b901b52cb64edd2ea6c | 69cede2a5a5f60e3f5602b901b52cb64edd2ea6c |
| linux | linux | >= d5c65159f2895379e11ca13f62feabe93278985d < 3f77c7d605b29df277d77e9ee75d96e7ad145d2d | 3f77c7d605b29df277d77e9ee75d96e7ad145d2d |
| linux | linux_kernel | >= 0 < 5.10.205-1 | 5.10.205-1 |
| linux | linux_kernel | >= 0 < 6.1.64-1 | 6.1.64-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 0 < 6.6.8-1 | 6.6.8-1 |
| linux | linux_kernel | >= 5.11 < 5.15.140 | 5.15.140 |
| linux | linux_kernel | >= 5.16 < 6.1.64 | 6.1.64 |
| linux | linux_kernel | >= 5.6 < 5.10.202 | 5.10.202 |
| linux | linux_kernel | >= 6.2 < 6.5.13 | 6.5.13 |
| linux | linux_kernel | >= 6.6 < 6.6.3 | 6.6.3 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: ath11k: fix htt pktlog locking
vendor_redhat·2024-05-21·CVSS 4.4
CVE-2023-52800 [MEDIUM] CWE-413 kernel: wifi: ath11k: fix htt pktlog locking
kernel: wifi: ath11k: fix htt pktlog locking
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix htt pktlog locking
The ath11k active pdevs are protected by RCU but the htt pktlog handling
code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a
read-side critical section.
Mark the code in question as an RCU read-side critical section to avoid
any potential use-after-free issues.
Compile tested only.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 9) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Lin
Debian
CVE-2023-52800: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath11...
vendor_debian·2023·CVSS 4.4
CVE-2023-52800 [MEDIUM] CVE-2023-52800: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath11...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix htt pktlog locking The ath11k active pdevs are protected by RCU but the htt pktlog handling code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a read-side critical section. Mark the code in question as an RCU read-side critical section to avoid any potential use-after-free issues. Compile tested only.
Scope: local
bookworm: resolved (fixed in 6.1.64-1)
bullseye: resolved (fixed in 5.10.205-1)
forky: resolved (fixed in 6.6.8-1)
sid: resolved (fixed in 6.6.8-1)
trixie: resolved (fixed in 6.6.8-1)
OSV
CVE-2023-52800: In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix htt pktlog locking The ath11k active pdevs are protected by RCU
osv·2024-05-21·CVSS 4.4
CVE-2023-52800 [MEDIUM] CVE-2023-52800: In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix htt pktlog locking The ath11k active pdevs are protected by RCU
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix htt pktlog locking The ath11k active pdevs are protected by RCU but the htt pktlog handling code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a read-side critical section. Mark the code in question as an RCU read-side critical section to avoid any potential use-after-free issues. Compile tested only.
GHSA
GHSA-5p99-hcg9-j3m3: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix htt pktlog locking
The ath11k active pdevs are protected by RC
ghsa_unreviewed·2024-05-21
CVE-2023-52800 [MEDIUM] CWE-416 GHSA-5p99-hcg9-j3m3: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix htt pktlog locking
The ath11k active pdevs are protected by RC
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: fix htt pktlog locking
The ath11k active pdevs are protected by RCU but the htt pktlog handling
code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a
read-side critical section.
Mark the code in question as an RCU read-side critical section to avoid
any potential use-after-free issues.
Compile tested only.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/03ed26935bebf6b6fd8a656490bf3dcc71b72679https://git.kernel.org/stable/c/3a51e6b4da71fdfa43ec006d6abc020f3e22d14ehttps://git.kernel.org/stable/c/3f77c7d605b29df277d77e9ee75d96e7ad145d2dhttps://git.kernel.org/stable/c/423762f021825b5e57c3d6f01ff96a9ff19cdcd8https://git.kernel.org/stable/c/69cede2a5a5f60e3f5602b901b52cb64edd2ea6chttps://git.kernel.org/stable/c/e3199b3fac65c9f103055390b6fd07c5cffa5961https://git.kernel.org/stable/c/03ed26935bebf6b6fd8a656490bf3dcc71b72679https://git.kernel.org/stable/c/3a51e6b4da71fdfa43ec006d6abc020f3e22d14ehttps://git.kernel.org/stable/c/3f77c7d605b29df277d77e9ee75d96e7ad145d2dhttps://git.kernel.org/stable/c/423762f021825b5e57c3d6f01ff96a9ff19cdcd8https://git.kernel.org/stable/c/69cede2a5a5f60e3f5602b901b52cb64edd2ea6chttps://git.kernel.org/stable/c/e3199b3fac65c9f103055390b6fd07c5cffa5961
2024-05-21
Published