CVE-2023-54131
published 2025-12-24CVE-2023-54131: In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: Fix memory leak when handling surveys When removing a rt2x00 device, its…
PriorityP420medium5.5
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 device, its associated channel surveys
are not freed, causing a memory leak observable with kmemleak:
unreferenced object 0xffff9620f0881a00 (size 512):
comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s)
hex dump (first 32 bytes):
70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............
00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................
backtrace:
[] __kmalloc+0x4b/0x130
[] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]
[] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]
[] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]
[] rt2x00usb_probe+0x1be/0x980 [rt2x00usb]
[] usb_probe_interface+0xe2/0x310 [usbcore]
[] really_probe+0x1a5/0x410
[] __driver_probe_device+0x78/0x180
[] driver_probe_device+0x1e/0x90
[] __driver_attach+0xd2/0x1c0
[] bus_for_each_dev+0x77/0xd0
[] bus_add_driver+0x112/0x210
[] driver_register+0x5c/0x120
[] usb_register_driver+0x88/0x150 [usbcore]
[] do_one_initcall+0x44/0x220
[] do_init_module+0x4c/0x220
Fix this by freeing the channel surveys on device removal.
Tested with a RT3070 based USB wireless adapter.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < eb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6af | eb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6af |
| linux | linux | >= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < bea3f8aa999318bdffa2d17753e492f76904f0ce | bea3f8aa999318bdffa2d17753e492f76904f0ce |
| linux | linux | >= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < 494064ffd60d044c097d514917c40913d1affbca | 494064ffd60d044c097d514917c40913d1affbca |
| linux | linux | >= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < 0354bce76ed1d775904acdb4cc0bf88c5b9b5b9f | 0354bce76ed1d775904acdb4cc0bf88c5b9b5b9f |
| linux | linux | >= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49 | cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 5.11.0 < 5.15.111 | 5.15.111 |
| linux | linux_kernel | >= 5.16.0 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 6.2.0 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3.0 < 6.3.2 | 6.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v5xj-7363-557x: In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 devic
ghsa_unreviewed·2025-12-24
CVE-2023-54131 GHSA-v5xj-7363-557x: In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 devic
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 device, its associated channel surveys
are not freed, causing a memory leak observable with kmemleak:
unreferenced object 0xffff9620f0881a00 (size 512):
comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s)
hex dump (first 32 bytes):
70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............
00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................
backtrace:
[] __kmalloc+0x4b/0x130
[] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]
[] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]
[] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]
[] rt2x00usb_probe+0x1be/0x980 [rt2x00usb]
[] usb_probe_interface+0xe2/0x310 [usbcore]
[] really_probe+0x1a5/0
OSV
wifi: rt2x00: Fix memory leak when handling surveys
osv·2025-12-24
CVE-2023-54131 wifi: rt2x00: Fix memory leak when handling surveys
wifi: rt2x00: Fix memory leak when handling surveys
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 device, its associated channel surveys
are not freed, causing a memory leak observable with kmemleak:
unreferenced object 0xffff9620f0881a00 (size 512):
comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s)
hex dump (first 32 bytes):
70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............
00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................
backtrace:
[] __kmalloc+0x4b/0x130
[] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]
[] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]
[] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]
[] rt2x00usb_probe+0x1be/0x980 [rt2x00usb]
[] usb_probe_i
OSV
CVE-2023-54131: In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: Fix memory leak when handling surveys When removing a rt2x00 device,
osv·2025-12-24
CVE-2023-54131 CVE-2023-54131: In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: Fix memory leak when handling surveys When removing a rt2x00 device,
In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: Fix memory leak when handling surveys When removing a rt2x00 device, its associated channel surveys are not freed, causing a memory leak observable with kmemleak: unreferenced object 0xffff9620f0881a00 (size 512): comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s) hex dump (first 32 bytes): 70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD.............. 00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................ backtrace: [] __kmalloc+0x4b/0x130 [] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib] [] rt2800usb_probe_hw+0xe/0x60 [rt2800usb] [] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib] [] rt2x00usb_probe+0x1be/0x980 [rt2x00usb] [] usb_probe_interface+0xe2/0x310 [usbcore] [] really_probe+0x1a5/0x41
Red Hat
kernel: Linux kernel rt2x00 Wi-Fi driver: Denial of Service via memory leak during device removal
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54131 [MEDIUM] CWE-772 kernel: Linux kernel rt2x00 Wi-Fi driver: Denial of Service via memory leak during device removal
kernel: Linux kernel rt2x00 Wi-Fi driver: Denial of Service via memory leak during device removal
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 device, its associated channel surveys
are not freed, causing a memory leak observable with kmemleak:
unreferenced object 0xffff9620f0881a00 (size 512):
comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s)
hex dump (first 32 bytes):
70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............
00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................
backtrace:
[] __kmalloc+0x4b/0x130
[] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]
[] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]
[] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]
[] rt2x00usb_p
Debian
CVE-2023-54131: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x0...
vendor_debian·2023
CVE-2023-54131 CVE-2023-54131: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x0...
In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: Fix memory leak when handling surveys When removing a rt2x00 device, its associated channel surveys are not freed, causing a memory leak observable with kmemleak: unreferenced object 0xffff9620f0881a00 (size 512): comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s) hex dump (first 32 bytes): 70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD.............. 00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................ backtrace: [] __kmalloc+0x4b/0x130 [] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib] [] rt2800usb_probe_hw+0xe/0x60 [rt2800usb] [] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib] [] rt2x00usb_probe+0x1be/0x980 [rt2x00usb] [] usb_probe_interface+0xe2/0x310 [usbcore] [] really_probe+0x1a5/0x41
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54131 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54131 CVE-2023-54131 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54131 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 device, its associated channel surveys
are not freed, causing a memory leak observable with kmemleak:
unreferenced object 0xffff9620f0881a00 (size 512):
comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s)
hex dump (first 32 bytes):
70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............
00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................
backtrace:
[ ] __kmalloc+0x4b/0x130
[ ] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]
[ ] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]
[ ] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]
[ ] rt2x00usb_probe+0x1be/0x980 [
Bugzilla
CVE-2023-54131 kernel: Linux kernel rt2x00 Wi-Fi driver: Denial of Service via memory leak during device removal
bugzilla·2025-12-24
CVE-2023-54131 [MEDIUM] CVE-2023-54131 kernel: Linux kernel rt2x00 Wi-Fi driver: Denial of Service via memory leak during device removal
CVE-2023-54131 kernel: Linux kernel rt2x00 Wi-Fi driver: Denial of Service via memory leak during device removal
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 device, its associated channel surveys
are not freed, causing a memory leak observable with kmemleak:
unreferenced object 0xffff9620f0881a00 (size 512):
comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s)
hex dump (first 32 bytes):
70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............
00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................
backtrace:
[] __kmalloc+0x4b/0x130
[] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]
[] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]
[] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00l
https://git.kernel.org/stable/c/0354bce76ed1d775904acdb4cc0bf88c5b9b5b9fhttps://git.kernel.org/stable/c/494064ffd60d044c097d514917c40913d1affbcahttps://git.kernel.org/stable/c/bea3f8aa999318bdffa2d17753e492f76904f0cehttps://git.kernel.org/stable/c/cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49https://git.kernel.org/stable/c/eb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6af
2025-12-24
Published