CVE-2023-54052Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix skb leak by txs missing in AMSDU txs may be dropped if the frame is aggregated in AMSDU. When the problem shows up, some SKBs would be hold in driver to cause network stopped temporarily. Even if the problem can be recovered by txs timeout handling, mt7921 still need to disable txs in AMSDU to avoid this issue.

Affected Packages4 packages

Linuxlinux/linux_kernel5.12.06.1.52+2
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linux163f4d22c118d4eb9e275bf9ee1577c0d14b32081cd102aaedb277fbe81dd08cd9f5cae951de2bff+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2023-54052: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix skb leak by txs missing in AMSDU txs may be dropped if the2025-12-24
GHSA
GHSA-4jff-2mpg-6xjx: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix skb leak by txs missing in AMSDU txs may be dropped if t2025-12-24
OSV
wifi: mt76: mt7921: fix skb leak by txs missing in AMSDU2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel Wi-Fi driver: Denial of Service due to missing transmit status2025-12-24
Debian
CVE-2023-54052: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54052 Impact, Exploitability, and Mitigation Steps | Wiz