CVE-2023-53802
published 2025-12-09CVE-2023-53802: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function It is…
PriorityP420medium6.1
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
It is stated that ath9k_htc_rx_msg() either frees the provided skb or
passes its management to another callback function. However, the skb is
not freed in case there is no another callback function, and Syzkaller was
able to cause a memory leak. Also minor comment fix.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < b11f95f65cc52ee3a756e6f6a88df37a203e25bd | b11f95f65cc52ee3a756e6f6a88df37a203e25bd |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 68171c006c8645a3e0293a6c3e6037c6538ac1c5 | 68171c006c8645a3e0293a6c3e6037c6538ac1c5 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 564bc2222bf50eb6cdee715a5431bf4dc9f923c1 | 564bc2222bf50eb6cdee715a5431bf4dc9f923c1 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < ec246dfe006b2a8f36353f7489e4f525114db9a5 | ec246dfe006b2a8f36353f7489e4f525114db9a5 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < c0c0614f143b568cd0e9525d53cf12e5dcd11987 | c0c0614f143b568cd0e9525d53cf12e5dcd11987 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 5a84e51f72580fc70066b03f3dac38421e702a0b | 5a84e51f72580fc70066b03f3dac38421e702a0b |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < bbfababb4f899fe1556eac195f9774b6fe675fb6 | bbfababb4f899fe1556eac195f9774b6fe675fb6 |
| linux | linux | >= fb9987d0f748c983bb795a86f47522313f701a08 < 9b25e3985477ac3f02eca5fc1e0cc6850a3f7e69 | 9b25e3985477ac3f02eca5fc1e0cc6850a3f7e69 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 2.6.35 < 4.14.308 | 4.14.308 |
| linux | linux_kernel | >= 4.15.0 < 4.19.276 | 4.19.276 |
| linux | linux_kernel | >= 4.20.0 < 5.4.235 | 5.4.235 |
| linux | linux_kernel | >= 5.11.0 < 5.15.99 | 5.15.99 |
| linux | linux_kernel | >= 5.16.0 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 5.5.0 < 5.10.173 | 5.10.173 |
| linux | linux_kernel | >= 6.2.0 < 6.2.3 | 6.2.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
osv·2025-12-09
CVE-2023-53802 wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
It is stated that ath9k_htc_rx_msg() either frees the provided skb or
passes its management to another callback function. However, the skb is
not freed in case there is no another callback function, and Syzkaller was
able to cause a memory leak. Also minor comment fix.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
OSV
CVE-2023-53802: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback funct
osv·2025-12-09
CVE-2023-53802 CVE-2023-53802: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback funct
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function It is stated that ath9k_htc_rx_msg() either frees the provided skb or passes its management to another callback function. However, the skb is not freed in case there is no another callback function, and Syzkaller was able to cause a memory leak. Also minor comment fix. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
GHSA
GHSA-47hx-9qjp-4jqg: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback func
ghsa_unreviewed·2025-12-09
CVE-2023-53802 GHSA-47hx-9qjp-4jqg: In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback func
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
It is stated that ath9k_htc_rx_msg() either frees the provided skb or
passes its management to another callback function. However, the skb is
not freed in case there is no another callback function, and Syzkaller was
able to cause a memory leak. Also minor comment fix.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Red Hat
kernel: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
vendor_redhat·2025-12-09·CVSS 6.1
CVE-2023-53802 [MEDIUM] CWE-771 kernel: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
kernel: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
It is stated that ath9k_htc_rx_msg() either frees the provided skb or
passes its management to another callback function. However, the skb is
not freed in case there is no another callback function, and Syzkaller was
able to cause a memory leak. Also minor comment fix.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Under investigation
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: ke
Debian
CVE-2023-53802: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k...
vendor_debian·2023
CVE-2023-53802 CVE-2023-53802: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function It is stated that ath9k_htc_rx_msg() either frees the provided skb or passes its management to another callback function. However, the skb is not freed in case there is no another callback function, and Syzkaller was able to cause a memory leak. Also minor comment fix. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/564bc2222bf50eb6cdee715a5431bf4dc9f923c1https://git.kernel.org/stable/c/5a84e51f72580fc70066b03f3dac38421e702a0bhttps://git.kernel.org/stable/c/68171c006c8645a3e0293a6c3e6037c6538ac1c5https://git.kernel.org/stable/c/9b25e3985477ac3f02eca5fc1e0cc6850a3f7e69https://git.kernel.org/stable/c/b11f95f65cc52ee3a756e6f6a88df37a203e25bdhttps://git.kernel.org/stable/c/bbfababb4f899fe1556eac195f9774b6fe675fb6https://git.kernel.org/stable/c/c0c0614f143b568cd0e9525d53cf12e5dcd11987https://git.kernel.org/stable/c/ec246dfe006b2a8f36353f7489e4f525114db9a5
2025-12-09
Published