[<prev] [next>] [day] [month] [year] [list]
Message-ID: <2025123002-CVE-2023-54275-728d@gregkh>
Date: Tue, 30 Dec 2025 13:20:41 +0100
From: Greg Kroah-Hartman <gregkh@...uxfoundation.org>
To: linux-cve-announce@...r.kernel.org
Cc: Greg Kroah-Hartman <gregkh@...nel.org>
Subject: CVE-2023-54275: wifi: ath11k: Fix memory leak in ath11k_peer_rx_frag_setup
From: Greg Kroah-Hartman <gregkh@...nel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: Fix memory leak in ath11k_peer_rx_frag_setup
crypto_alloc_shash() allocates resources, which should be released by
crypto_free_shash(). When ath11k_peer_find() fails, there has memory
leak. Add missing crypto_free_shash() to fix this.
The Linux kernel CVE team has assigned CVE-2023-54275 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.7 with commit 243874c64c8137bc90455200a7735da72836ecab and fixed in 5.10.173 with commit 137963e3b95776f1d57c62f249a93fe47e019a22
Issue introduced in 5.7 with commit 243874c64c8137bc90455200a7735da72836ecab and fixed in 5.15.99 with commit 53c8a256e5d3f31d80186de03a3d2a7f747b2aa0
Issue introduced in 5.7 with commit 243874c64c8137bc90455200a7735da72836ecab and fixed in 6.1.16 with commit e596b36e15a7158b0bb2d55077b6b381ee41020c
Issue introduced in 5.7 with commit 243874c64c8137bc90455200a7735da72836ecab and fixed in 6.2.3 with commit 64a78ec4f4579798d8e885aca9bdd707bca6b16b
Issue introduced in 5.7 with commit 243874c64c8137bc90455200a7735da72836ecab and fixed in 6.3 with commit ed3f83b3459a67a3ab9d806490ac304b567b1c2d
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2023-54275
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/net/wireless/ath/ath11k/dp_rx.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/137963e3b95776f1d57c62f249a93fe47e019a22
https://git.kernel.org/stable/c/53c8a256e5d3f31d80186de03a3d2a7f747b2aa0
https://git.kernel.org/stable/c/e596b36e15a7158b0bb2d55077b6b381ee41020c
https://git.kernel.org/stable/c/64a78ec4f4579798d8e885aca9bdd707bca6b16b
https://git.kernel.org/stable/c/ed3f83b3459a67a3ab9d806490ac304b567b1c2d
Powered by blists - more mailing lists