CVE-2023-53185
published 2025-09-15CVE-2023-53185: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes A bad USB device is able to…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
A bad USB device is able to construct a service connection response
message with target endpoint being ENDPOINT0 which is reserved for
HTC_CTRL_RSVD_SVC and should not be modified to be used for any other
services.
Reject such service connection responses.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < db8df00cd6d801b3abdb145201c2bdd1c665f585 | db8df00cd6d801b3abdb145201c2bdd1c665f585 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 9e3031eea2d45918dc44cbfc6a6029e82882916f | 9e3031eea2d45918dc44cbfc6a6029e82882916f |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 4dc3560561a08842b4a4c07ccc5a90e5067dbb5b | 4dc3560561a08842b4a4c07ccc5a90e5067dbb5b |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 1044187e7249073f719ebbf9e5ffb4f16f99e555 | 1044187e7249073f719ebbf9e5ffb4f16f99e555 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 95b4b940f0fb2873dcedad81699e869eb7581c85 | 95b4b940f0fb2873dcedad81699e869eb7581c85 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 09740fa9827cfbaf23ecd041e602a426f99be888 | 09740fa9827cfbaf23ecd041e602a426f99be888 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 6a444dffb75238c47d2d852f12cf53f12ad2cba8 | 6a444dffb75238c47d2d852f12cf53f12ad2cba8 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < be2a546c30fe8d72efa032bee612363bb75314bd | be2a546c30fe8d72efa032bee612363bb75314bd |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 061b0cb9327b80d7a0f63a33e7c3e2a91a71f142 | 061b0cb9327b80d7a0f63a33e7c3e2a91a71f142 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 2.6.35 < 4.14.322 | 4.14.322 |
| linux | linux_kernel | >= 4.15 < 4.19.291 | 4.19.291 |
| linux | linux_kernel | >= 4.20 < 5.4.251 | 5.4.251 |
| linux | linux_kernel | >= 5.11 < 5.15.121 | 5.15.121 |
| linux | linux_kernel | >= 5.16 < 6.1.39 | 6.1.39 |
| linux | linux_kernel | >= 5.5 < 5.10.188 | 5.10.188 |
| linux | linux_kernel | >= 6.2 < 6.3.13 | 6.3.13 |
| linux | linux_kernel | >= 6.4 < 6.4.4 | 6.4.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2023-53185 [MEDIUM] CWE-1285 kernel: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
kernel: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
A bad USB device is able to construct a service connection response
message with target endpoint being ENDPOINT0 which is reserved for
HTC_CTRL_RSVD_SVC and should not be modified to be used for any other
services.
Reject such service connection responses.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red H
Debian
CVE-2023-53185: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k...
vendor_debian·2023·CVSS 5.5
CVE-2023-53185 [MEDIUM] CVE-2023-53185: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes A bad USB device is able to construct a service connection response message with target endpoint being ENDPOINT0 which is reserved for HTC_CTRL_RSVD_SVC and should not be modified to be used for any other services. Reject such service connection responses. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Scope: local
bookworm: resolved (fixed in 6.1.52-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.4.4-1)
sid: resolved (fixed in 6.4.4-1)
trixie: resolved (fixed in 6.4.4-1)
OSV
CVE-2023-53185: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes A bad USB device is abl
osv·2025-09-15·CVSS 5.5
CVE-2023-53185 [MEDIUM] CVE-2023-53185: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes A bad USB device is abl
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes A bad USB device is able to construct a service connection response message with target endpoint being ENDPOINT0 which is reserved for HTC_CTRL_RSVD_SVC and should not be modified to be used for any other services. Reject such service connection responses. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
GHSA
GHSA-mj4m-3482-q62h: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
A bad USB device is a
ghsa_unreviewed·2025-09-15
CVE-2023-53185 [MEDIUM] GHSA-mj4m-3482-q62h: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
A bad USB device is a
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes
A bad USB device is able to construct a service connection response
message with target endpoint being ENDPOINT0 which is reserved for
HTC_CTRL_RSVD_SVC and should not be modified to be used for any other
services.
Reject such service connection responses.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/061b0cb9327b80d7a0f63a33e7c3e2a91a71f142https://git.kernel.org/stable/c/09740fa9827cfbaf23ecd041e602a426f99be888https://git.kernel.org/stable/c/1044187e7249073f719ebbf9e5ffb4f16f99e555https://git.kernel.org/stable/c/4dc3560561a08842b4a4c07ccc5a90e5067dbb5bhttps://git.kernel.org/stable/c/6a444dffb75238c47d2d852f12cf53f12ad2cba8https://git.kernel.org/stable/c/95b4b940f0fb2873dcedad81699e869eb7581c85https://git.kernel.org/stable/c/9e3031eea2d45918dc44cbfc6a6029e82882916fhttps://git.kernel.org/stable/c/be2a546c30fe8d72efa032bee612363bb75314bdhttps://git.kernel.org/stable/c/db8df00cd6d801b3abdb145201c2bdd1c665f585
2025-09-15
Published