PT-2025-37641 · Linux+2 · Linux Kernel+2

Published

2023-01-17

·

Updated

2025-11-14

·

CVE-2023-53199

CVSS v2.0

6.1

Medium

VectorAV:A/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a memory leak in the ath9k hif usb rx stream() function within the ath9k USB Host Interface (HIF) driver. Syzkaller detected that when processing skbs (socket buffers) in this function, allocated skbs in the skb pool are not freed if ath9k hif usb rx stream() fails due to an incorrect packet length or tag. This results in a memory leak. The patch addresses this by ensuring that associated packets in the skb pool are dropped and freed when an invalid skb is detected, and by nullifying the remain skb pointer after processing to prevent potential use-after-free issues.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

BDU:2026-02518
CVE-2023-53199
OESA-2025-2659
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Suse