wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function
Published Dec 9, 2025
6.1
MEDIUMCVSS 3.1
EPSS 0.19%
Description
It is stated that ath9k_htc_rx_msg() either frees the provided skb or passes its management to another callback function. However, the skb is not freed in case there is no another callback function, and Syzkaller was able to cause a memory leak. Also minor comment fix.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.35StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.35
- Version 4.14.308StatusunaffectedConstraints<=4.14.*
- Version 4.19.276StatusunaffectedConstraints<=4.19.*
- Version 5.10.173StatusunaffectedConstraints<=5.10.*
- Version 5.15.99StatusunaffectedConstraints<=5.15.*
- Version 5.4.235StatusunaffectedConstraints<=5.4.*
- Version 6.1.16StatusunaffectedConstraints<=6.1.*
- Version 6.2.3StatusunaffectedConstraints<=6.2.*
- Version 6.3StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2023-53802 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2420288 Issue Tracking
- https://git.kernel.org/stable/c/564bc2222bf50eb6cdee715a5431bf4dc9f923c1
- https://git.kernel.org/stable/c/5a84e51f72580fc70066b03f3dac38421e702a0b
- https://git.kernel.org/stable/c/68171c006c8645a3e0293a6c3e6037c6538ac1c5
- https://git.kernel.org/stable/c/9b25e3985477ac3f02eca5fc1e0cc6850a3f7e69
- https://git.kernel.org/stable/c/b11f95f65cc52ee3a756e6f6a88df37a203e25bd
- https://git.kernel.org/stable/c/bbfababb4f899fe1556eac195f9774b6fe675fb6
- https://git.kernel.org/stable/c/c0c0614f143b568cd0e9525d53cf12e5dcd11987
- https://git.kernel.org/stable/c/ec246dfe006b2a8f36353f7489e4f525114db9a5
- https://lore.kernel.org/linux-cve-announce/2025120943-CVE-2023-53802-4ffb@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-53802
- https://www.cve.org/CVERecord?id=CVE-2023-53802
Change history (0)
No recorded changes yet.