ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2023-54300

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: avoid referencing uninit memory in ath9k_wmi_ctrl_rx For the reasons also described in commit b383e8abed41 ("wifi: ath9k: avoid uninit memory read in ath9k_htc_rx_msg()"), ath9k_htc_rx_msg() should validate pkt_len before accessing the SKB. For example, the obtained SKB may have been badly constructed with pkt_len = 8. In this case, the SKB can only contain a valid htc_frame_hdr but after being processed in ath9k_htc_rx_msg() and passed to ath9k_wmi_ctrl_rx() endpoint RX handler, it is expected to have a WMI command header which should be located inside its data payload. Implement sanity checking inside ath9k_wmi_ctrl_rx(). Otherwise, uninit memory can be referenced. Tested on Qualcomm Atheros Communications AR9271 802.11n . Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
-
CVSS
0.0
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21cve.orginitial, patch: Unavailable0.0

Affected Software
VendorProductVersion
LinuxLinux≥ 6.4.4, ≤ 6.4.*
LinuxLinux< 90e3c10177573b8662ac9858abd9bf73
LinuxLinux≥ 6.5, ≤ *
LinuxLinux< 250efb4d3f5b32a115ea6bf25437ba44
LinuxLinux≥ 4.14.322, ≤ 4.14.*
LinuxLinux< ad5425e70789c29b93acafb5bb4629e4
LinuxLinux≥ 4.19.291, ≤ 4.19.*
LinuxLinux< d1c2ff2bd84c3692c9df267a2b991ce9
LinuxLinux≥ 5.4.251, ≤ 5.4.*
LinuxLinux< 8ed572e52714593b209e3aa352406aff
LinuxLinux≥ 5.10.188, ≤ 5.10.*
LinuxLinux< 75acec91aeaa07375cd5f418069e61b1
LinuxLinux≥ 5.15.121, ≤ 5.15.*
LinuxLinux< f24292e827088bba8de7158501ac25a5
LinuxLinux≥ 6.1.39, ≤ 6.1.*
LinuxLinux≥ 6.3.13, ≤ 6.3.*
LinuxLinux< 0bc12e41af4e3ae1f0efecc377f05144
LinuxLinux< 2.6.35
LinuxLinux< 28259ce4f1f1f9ab37fa817756c89098
LinuxLinux2.6.35
Published: 2025-12-30