CVE-2023-53540
published 2025-10-04CVE-2023-53540: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: reject auth/assoc to AP with our address
If the AP uses our own address as its MLD address or BSSID, then
clearly something's wrong. Reject such connections so we don't
try and fail later.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 19957bb399e2722719c0e20c9ae91cf8b6aaff04 < 676a423410131d111a264d29aecbe6aadd57fb22 | 676a423410131d111a264d29aecbe6aadd57fb22 |
| linux | linux | >= 19957bb399e2722719c0e20c9ae91cf8b6aaff04 < 07added2c6cd63de047bc786b39436322abb67c0 | 07added2c6cd63de047bc786b39436322abb67c0 |
| linux | linux | >= 19957bb399e2722719c0e20c9ae91cf8b6aaff04 < 5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 | 5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 0 < 6.5.6-1 | 6.5.6-1 |
| linux | linux_kernel | >= 2.6.32 < 6.1.55 | 6.1.55 |
| linux | linux_kernel | >= 6.2 < 6.5.5 | 6.5.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53540: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own ad
osv·2025-10-04·CVSS 5.5
CVE-2023-53540 [MEDIUM] CVE-2023-53540: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own ad
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as its MLD address or BSSID, then clearly something's wrong. Reject such connections so we don't try and fail later.
GHSA
GHSA-83qc-9rcf-r226: In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: reject auth/assoc to AP with our address
If the AP uses our own
ghsa_unreviewed·2025-10-04
CVE-2023-53540 [MEDIUM] GHSA-83qc-9rcf-r226: In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: reject auth/assoc to AP with our address
If the AP uses our own
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: reject auth/assoc to AP with our address
If the AP uses our own address as its MLD address or BSSID, then
clearly something's wrong. Reject such connections so we don't
try and fail later.
Red Hat
kernel: wifi: cfg80211: reject auth/assoc to AP with our address
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2023-53540 [MEDIUM] CWE-20 kernel: wifi: cfg80211: reject auth/assoc to AP with our address
kernel: wifi: cfg80211: reject auth/assoc to AP with our address
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: reject auth/assoc to AP with our address
If the AP uses our own address as its MLD address or BSSID, then
clearly something's wrong. Reject such connections so we don't
try and fail later.
Statement: A flaw in cfg80211 allowed authentication or association attempts to an access point using the device’s own MAC address, leading to kernel instability or denial of service. The issue is not remotely exploitable and requires the ability to issue crafted nl80211 netlink commands — therefore for the CVSS the PR:H (high privileges) applies.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) -
Debian
CVE-2023-53540: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80...
vendor_debian·2023·CVSS 5.5
CVE-2023-53540 [MEDIUM] CVE-2023-53540: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80...
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as its MLD address or BSSID, then clearly something's wrong. Reject such connections so we don't try and fail later.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: open
forky: resolved (fixed in 6.5.6-1)
sid: resolved (fixed in 6.5.6-1)
trixie: resolved (fixed in 6.5.6-1)
No detection rules found.
No public exploits indexed.
2025-10-04
Published