cbcvebase.
CVE-2023-54016
published 2025-12-24

CVE-2023-54016: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix memory leak in rx_desc and tx_desc Currently when…

PriorityP417medium5.5
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix memory leak in rx_desc and tx_desc Currently when ath12k_dp_cc_desc_init() is called we allocate memory to rx_descs and tx_descs. In ath12k_dp_cc_cleanup(), during descriptor cleanup rx_descs and tx_descs memory is not freed. This is cause of memory leak. These allocated memory should be freed in ath12k_dp_cc_cleanup. In ath12k_dp_cc_desc_init(), we can save base address of rx_descs and tx_descs. In ath12k_dp_cc_cleanup(), we can free rx_descs and tx_descs memory using their base address. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.5.6-1 (forky)linux 6.5.6-1 (forky)
linuxlinux
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < e16be2d34883eecfe7fd888fcdb76c7a5db5d187e16be2d34883eecfe7fd888fcdb76c7a5db5d187
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < afb522b36e76acaa9f8fc06d0a9742d841c47c16afb522b36e76acaa9f8fc06d0a9742d841c47c16
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 6.3.0 < 6.5.56.5.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.