cbcvebase.
CVE-2023-54300
published 2025-12-30

CVE-2023-54300: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: avoid referencing uninit memory in ath9k_wmi_ctrl_rx For the reasons also…

PriorityP422medium6.6
EPSS
0.20%
10.4th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: avoid referencing uninit memory in ath9k_wmi_ctrl_rx For the reasons also described in commit b383e8abed41 ("wifi: ath9k: avoid uninit memory read in ath9k_htc_rx_msg()"), ath9k_htc_rx_msg() should validate pkt_len before accessing the SKB. For example, the obtained SKB may have been badly constructed with pkt_len = 8. In this case, the SKB can only contain a valid htc_frame_hdr but after being processed in ath9k_htc_rx_msg() and passed to ath9k_wmi_ctrl_rx() endpoint RX handler, it is expected to have a WMI command header which should be located inside its data payload. Implement sanity checking inside ath9k_wmi_ctrl_rx(). Otherwise, uninit memory can be referenced. Tested on Qualcomm Atheros Communications AR9271 802.11n . Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 0bc12e41af4e3ae1f0efecc377f0514459df07070bc12e41af4e3ae1f0efecc377f0514459df0707
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 28259ce4f1f1f9ab37fa817756c89098213d2fc028259ce4f1f1f9ab37fa817756c89098213d2fc0
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 90e3c10177573b8662ac9858abd9bf731d5d98e090e3c10177573b8662ac9858abd9bf731d5d98e0
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 250efb4d3f5b32a115ea6bf25437ba44a1b3c04f250efb4d3f5b32a115ea6bf25437ba44a1b3c04f
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < ad5425e70789c29b93acafb5bb4629e4eb908296ad5425e70789c29b93acafb5bb4629e4eb908296
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < d1c2ff2bd84c3692c9df267a2b991ce92bfca8efd1c2ff2bd84c3692c9df267a2b991ce92bfca8ef
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 8ed572e52714593b209e3aa352406aff844811798ed572e52714593b209e3aa352406aff84481179
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 75acec91aeaa07375cd5f418069e61b16d39bbad75acec91aeaa07375cd5f418069e61b16d39bbad
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < f24292e827088bba8de7158501ac25a59b064953f24292e827088bba8de7158501ac25a59b064953
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 2.6.35 < 4.14.3224.14.322
linuxlinux_kernel>= 4.15.0 < 4.19.2914.19.291
linuxlinux_kernel>= 4.20.0 < 5.4.2515.4.251
linuxlinux_kernel>= 5.11.0 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16.0 < 6.1.396.1.39
linuxlinux_kernel>= 5.5.0 < 5.10.1885.10.188
linuxlinux_kernel>= 6.2.0 < 6.3.136.3.13
linuxlinux_kernel>= 6.4.0 < 6.4.46.4.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.