cbcvebase.
CVE-2023-54131
published 2025-12-24

CVE-2023-54131: In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: Fix memory leak when handling surveys When removing a rt2x00 device, its…

PriorityP420medium5.5
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: Fix memory leak when handling surveys When removing a rt2x00 device, its associated channel surveys are not freed, causing a memory leak observable with kmemleak: unreferenced object 0xffff9620f0881a00 (size 512): comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s) hex dump (first 32 bytes): 70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD.............. 00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................ backtrace: [] __kmalloc+0x4b/0x130 [] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib] [] rt2800usb_probe_hw+0xe/0x60 [rt2800usb] [] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib] [] rt2x00usb_probe+0x1be/0x980 [rt2x00usb] [] usb_probe_interface+0xe2/0x310 [usbcore] [] really_probe+0x1a5/0x410 [] __driver_probe_device+0x78/0x180 [] driver_probe_device+0x1e/0x90 [] __driver_attach+0xd2/0x1c0 [] bus_for_each_dev+0x77/0xd0 [] bus_add_driver+0x112/0x210 [] driver_register+0x5c/0x120 [] usb_register_driver+0x88/0x150 [usbcore] [] do_one_initcall+0x44/0x220 [] do_init_module+0x4c/0x220 Fix this by freeing the channel surveys on device removal. Tested with a RT3070 based USB wireless adapter.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < eb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6afeb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6af
linuxlinux>= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < bea3f8aa999318bdffa2d17753e492f76904f0cebea3f8aa999318bdffa2d17753e492f76904f0ce
linuxlinux>= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < 494064ffd60d044c097d514917c40913d1affbca494064ffd60d044c097d514917c40913d1affbca
linuxlinux>= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < 0354bce76ed1d775904acdb4cc0bf88c5b9b5b9f0354bce76ed1d775904acdb4cc0bf88c5b9b5b9f
linuxlinux>= 5447626910f5b8d964761ed4fa4feaf1a3ac47d0 < cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 5.11.0 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16.0 < 6.1.286.1.28
linuxlinux_kernel>= 6.2.0 < 6.2.156.2.15
linuxlinux_kernel>= 6.3.0 < 6.3.26.3.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.