wifi: ath9k: hif_usb: fix memory leak of remain_skbs
Published Oct 7, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
hif_dev->remain_skb is allocated and used exclusively in ath9k_hif_usb_rx_stream(). It is implied that an allocated remain_skb is processed and subsequently freed (in error paths) only during the next call of ath9k_hif_usb_rx_stream().
So, if the urbs are deallocated between those two calls due to the device deinitialization or suspend, it is possible that ath9k_hif_usb_rx_stream() is not called next time and the allocated remain_skb is leaked. Our local Syzkaller instance was able to trigger that.
remain_skb makes sense when receiving two consecutive urbs which are logically linked together, i.e. a specific data field from the first skb indicates a cached skb to be allocated, memcpy'd with some data and subsequently processed in the next call to ath9k_hif_usb_rx_stream(). Urbs deallocation supposedly makes that link irrelevant so we need to free the cached skb in those cases.
Fix the leak by introducing a function to explicitly free remain_skb (if it is not NULL) when the rx urbs have been deallocated. remain_skb is NULL when it has not been allocated at all (hif_dev struct is kzalloced) or when it has been processed in next call to ath9k_hif_usb_rx_stream().
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.35
Unaffected
- ≥ 0, < 2.6.35
- ≥ 4.19.283, ≤ 4.19.*
- ≥ 5.10.180, ≤ 5.10.*
- ≥ 5.15.111, ≤ 5.15.*
- ≥ 5.4.243, ≤ 5.4.*
- ≥ 6.1.28, ≤ 6.1.*
- ≥ 6.2.15, ≤ 6.2.*
- ≥ 6.3.2, ≤ 6.3.*
- 6.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 2.6.35 · < 4.19.283
- ≥ 4.20 · < 5.4.243
- ≥ 5.5 · < 5.10.180
- ≥ 5.11 · < 5.15.111
- ≥ 5.16 · < 6.1.28
- ≥ 6.2 · < 6.2.15
- ≥ 6.3 · < 6.3.2
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-513.5.1.el8_9
Fixed · RHSA-2023:7077
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-513.5.1.el8_9 | Fixed | RHSA-2023:7077 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Memory leak.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-53641 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2402188 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-31996 Advisory
- https://git.kernel.org/stable/c/320d760a35273aa815d58b57e4fd9ba5279a3489 Patch
- https://git.kernel.org/stable/c/59073060fe0950c6ecbe12bdc06469dcac62128d Patch
- https://git.kernel.org/stable/c/6719e3797ec52cd144c8a5ba8aaab36674800585 Patch
- https://git.kernel.org/stable/c/7654cc03eb699297130b693ec34e25f77b17c947 Patch
- https://git.kernel.org/stable/c/8f02d538878c9b1501f624595eb22ee4e5e0ff84 Patch
- https://git.kernel.org/stable/c/9b9356a3014123f0ce4b50d9278c1265173150ab Patch
- https://git.kernel.org/stable/c/d9899318660791141ea6002fda5577b2c5d7386e Patch
- https://git.kernel.org/stable/c/f0931fc8f4b6847c72e170d2326861c0a081d680 Patch
- https://lore.kernel.org/linux-cve-announce/2025100716-CVE-2023-53641-ed0e@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53641
- https://www.cve.org/CVERecord?id=CVE-2023-53641
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data