CVE-2023-53574Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: delete timer and free skb queue when unloading Fix possible crash and memory leak on driver unload by deleting TX purge timer and freeing C2H queue in 'rtw_core_deinit()', shrink critical section in the latter by freeing COEX queue out of TX report lock scope.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.26.5.5
Debianlinux/linux_kernel< 6.5.6-1+1
CVEListV5linux/linuxe3037485c68ec1a299ff41160d8fedbd4abc29b94128b00a6006870e117ab1841e58f369e9284ecb+2
debiandebian/linux< linux 6.5.6-1 (forky)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2mm9-p89h-xj5v: In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: delete timer and free skb queue when unloading Fix possible crash a2025-10-04
OSV
CVE-2023-53574: In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: delete timer and free skb queue when unloading Fix possible crash and2025-10-04

📋Vendor Advisories

2
Red Hat
kernel: wifi: rtw88: delete timer and free skb queue when unloading2025-10-04
Debian
CVE-2023-53574: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88...2023