CVE-2023-53717
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix potential stack-out-of-bounds write in ath9k_wmi_rsp_callback() Fix a stack-out-of-bounds write that occurs in a WMI response callback function that is called after a timeout occurs in ath9k_wmi_cmd(). The callback writes to wmi->cmd_rsp_buf, a stack-allocated buffer that could no longer be valid when a timeout occurs. Set wmi->last_seq_id to 0 when a timeout occurred. Found by a modified version of syzkaller. BUG: KASAN: stack-out-of-bounds in ath9k_wmi_ctrl_rx Write of size 4 Call Trace: memcpy ath9k_wmi_ctrl_rx ath9k_htc_rx_msg ath9k_hif_usb_reg_in_cb __usb_hcd_giveback_urb usb_hcd_giveback_urb dummy_timer call_timer_fn run_timer_softirq __do_softirq irq_exit_rcu sysvec_apic_timer_interrupt
EPSS Trends
Current EPSS score: 0.19%• Percentile: 10%
Affected Systems
- debian•linux
< 5.10.178-1 | < 6.1.20-1 | < 6.1.20-1 | < 6.1.20-1
- ubuntu•linux
all | < 5.4.0-152.169 | < 5.15.0-75.82
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
all | < 5.4.0-1104.112 | < 5.15.0-1038.43
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1038.43~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1104.112~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-fips
all | < 5.4.0-1104.112+fips1
- ubuntu•linux-aws-hwe
all
- ubuntu•linux-azure
all | all | < 5.4.0-1110.116 | < 5.15.0-1040.47
- ubuntu•linux-azure-4.15
all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1040.47~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1110.116~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fips
all | < 5.4.0-1110.116+fips1
- ubuntu•linux-bluefield
all | < 5.4.0-1065.71 | < 5.15.0-1019.21
- ubuntu•linux-fips
all | < 5.4.0-1079.88
- ubuntu•linux-gcp
all | all | < 5.4.0-1107.116 | < 5.15.0-1036.44
- ubuntu•linux-gcp-4.15
all
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1036.44~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1107.116~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gcp-6.2
all
- ubuntu•linux-gcp-6.5
all
- ubuntu•linux-gcp-fips
all | < 5.4.0-1107.116+fips1
- ubuntu•linux-gke
all | < 5.15.0-1036.41
- ubuntu•linux-gke-4.15
all
Showing first 50 affected entries in server-rendered view.
References (12)
- https://git.kernel.org/stable/c/89a33c3c847b19b19205cde1d924df2a6c70d8eb
- https://git.kernel.org/stable/c/ae4933b4f17de8e2b7ff6f91b17d3b0099a6d6bc
- https://git.kernel.org/stable/c/bf6dc175a2b53098a69db1236d9d53982f4b1bc0
- https://git.kernel.org/stable/c/78b56b0a613a87b61290b95be497fdfe2fe58aa6
- https://git.kernel.org/stable/c/1af7eacfad45149c54893a8a9df9e92ef89f0a90
- https://git.kernel.org/stable/c/8f28513d9520184059530c01a9f928a1b3809d3f
- https://git.kernel.org/stable/c/554048a72d7ecfdd58cc1bfb56e0a1864e64e82c
- https://git.kernel.org/stable/c/8a2f35b9830692f7a616f2f627f943bc748af13a
- https://ubuntu.com/security/CVE-2023-53717
- https://www.cve.org/CVERecord?id=CVE-2023-53717
- https://git.kernel.org/linus/8a2f35b9830692f7a616f2f627f943bc748af13a
- https://security-tracker.debian.org/tracker/CVE-2023-53717