CVE-2023-54131
Estado: AplazadaSin puntuar—
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: Fix memory leak when handling surveys
When removing a rt2x00 device, its associated channel surveys are not freed, causing a memory leak observable with kmemleak:
Fix this by freeing the channel surveys on device removal.
Tested with a RT3070 based USB wireless adapter.
Detalles técnicos trazas, registros y código del informe original
unreferenced object 0xffff9620f0881a00 (size 512):
comm "systemd-udevd", pid 2290, jiffies 4294906974 (age 33.768s)
hex dump (first 32 bytes):
70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............
00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................
backtrace:
[<ffffffffb0ed858b>] __kmalloc+0x4b/0x130
[<ffffffffc1b0f29b>] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]
[<ffffffffc1a9496e>] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]
[<ffffffffc1ae491a>] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]
[<ffffffffc1b3b83e>] rt2x00usb_probe+0x1be/0x980 [rt2x00usb]
[<ffffffffc05981e2>] usb_probe_interface+0xe2/0x310 [usbcore]
[<ffffffffb13be2d5>] really_probe+0x1a5/0x410
[<ffffffffb13be5c8>] __driver_probe_device+0x78/0x180
[<ffffffffb13be6fe>] driver_probe_device+0x1e/0x90
[<ffffffffb13be972>] __driver_attach+0xd2/0x1c0
[<ffffffffb13bbc57>] bus_for_each_dev+0x77/0xd0
[<ffffffffb13bd2a2>] bus_add_driver+0x112/0x210
[<ffffffffb13bfc6c>] driver_register+0x5c/0x120
[<ffffffffc0596ae8>] usb_register_driver+0x88/0x150 [usbcore]
[<ffffffffb0c011c4>] do_one_initcall+0x44/0x220
[<ffffffffb0d6134c>] do_init_module+0x4c/0x220CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0354bce76ed1d775904acdb4cc0bf88c5b9b5b9f
- https://git.kernel.org/stable/c/494064ffd60d044c097d514917c40913d1affbca
- https://git.kernel.org/stable/c/bea3f8aa999318bdffa2d17753e492f76904f0ce
- https://git.kernel.org/stable/c/cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49
- https://git.kernel.org/stable/c/eb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6af
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-54131",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5447626910f5b8d964761ed4fa4feaf1a3ac47d0",
"lessThan": "eb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6af",
"versionType": "git"
},
{
"status": "affected",
"version": "5447626910f5b8d964761ed4fa4feaf1a3ac47d0",
"lessThan": "bea3f8aa999318bdffa2d17753e492f76904f0ce",
"versionType": "git"
},
{
"status": "affected",
"version": "5447626910f5b8d964761ed4fa4feaf1a3ac47d0",
"lessThan": "494064ffd60d044c097d514917c40913d1affbca",
"versionType": "git"
},
{
"status": "affected",
"version": "5447626910f5b8d964761ed4fa4feaf1a3ac47d0",
"lessThan": "0354bce76ed1d775904acdb4cc0bf88c5b9b5b9f",
"versionType": "git"
},
{
"status": "affected",
"version": "5447626910f5b8d964761ed4fa4feaf1a3ac47d0",
"lessThan": "cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/wireless/ralink/rt2x00/rt2x00dev.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.111",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.28",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.2.15",
"versionType": "semver",
"lessThanOrEqual": "6.2.*"
},
{
"status": "unaffected",
"version": "6.3.2",
"versionType": "semver",
"lessThanOrEqual": "6.3.*"
},
{
"status": "unaffected",
"version": "6.4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/ralink/rt2x00/rt2x00dev.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-24T13:16:15.087",
"references": [
{
"url": "https://git.kernel.org/stable/c/0354bce76ed1d775904acdb4cc0bf88c5b9b5b9f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/494064ffd60d044c097d514917c40913d1affbca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bea3f8aa999318bdffa2d17753e492f76904f0ce",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cbef9a83c51dfcb07f77cfa6ac26f53a1ea86f49",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eb77c0c0a17c53d83b5fe8e46490fb0a7ed9e6af",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rt2x00: Fix memory leak when handling surveys\n\nWhen removing a rt2x00 device, its associated channel surveys\nare not freed, causing a memory leak observable with kmemleak:\n\nunreferenced object 0xffff9620f0881a00 (size 512):\n comm \"systemd-udevd\", pid 2290, jiffies 4294906974 (age 33.768s)\n hex dump (first 32 bytes):\n 70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00 pD..............\n 00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00 ................\n backtrace:\n [<ffffffffb0ed858b>] __kmalloc+0x4b/0x130\n [<ffffffffc1b0f29b>] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]\n [<ffffffffc1a9496e>] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]\n [<ffffffffc1ae491a>] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]\n [<ffffffffc1b3b83e>] rt2x00usb_probe+0x1be/0x980 [rt2x00usb]\n [<ffffffffc05981e2>] usb_probe_interface+0xe2/0x310 [usbcore]\n [<ffffffffb13be2d5>] really_probe+0x1a5/0x410\n [<ffffffffb13be5c8>] __driver_probe_device+0x78/0x180\n [<ffffffffb13be6fe>] driver_probe_device+0x1e/0x90\n [<ffffffffb13be972>] __driver_attach+0xd2/0x1c0\n [<ffffffffb13bbc57>] bus_for_each_dev+0x77/0xd0\n [<ffffffffb13bd2a2>] bus_add_driver+0x112/0x210\n [<ffffffffb13bfc6c>] driver_register+0x5c/0x120\n [<ffffffffc0596ae8>] usb_register_driver+0x88/0x150 [usbcore]\n [<ffffffffb0c011c4>] do_one_initcall+0x44/0x220\n [<ffffffffb0d6134c>] do_init_module+0x4c/0x220\n\nFix this by freeing the channel surveys on device removal.\n\nTested with a RT3070 based USB wireless adapter."
}
],
"lastModified": "2026-06-17T06:46:51.513",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}