cbcvebase.
CVE-2023-53602
published 2025-10-04

CVE-2023-53602: In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix memory leak in WMI firmware stats Memory allocated for firmware pdev…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.3th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix memory leak in WMI firmware stats Memory allocated for firmware pdev, vdev and beacon statistics are not released during rmmod. Fix it by calling ath11k_fw_stats_free() function before hardware unregister. While at it, avoid calling ath11k_fw_stats_free() while processing the firmware stats received in the WMI event because the local list is getting spliced and reinitialised and hence there are no elements in the list after splicing. Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 86f9330a49d1464849482298dd34d361859183eb86f9330a49d1464849482298dd34d361859183eb
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 55248d36beb79d3a61c9fb3122dc377fff523c8955248d36beb79d3a61c9fb3122dc377fff523c89
linuxlinux>= d5c65159f2895379e11ca13f62feabe93278985d < 6aafa1c2d3e3fea2ebe84c018003f2a91722e6076aafa1c2d3e3fea2ebe84c018003f2a91722e607
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 5.6 < 6.1.426.1.42
linuxlinux_kernel>= 6.2 < 6.4.76.4.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.