PT-2025-40712 · Linux+3 · Linux Kernel+3

Published

2022-05-10

·

Updated

2025-11-28

·

CVE-2023-53570

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An integer overflow exists in the nl80211 parse mbssid elems() function within the nl80211 module. The function uses a u8 variable, num elems, to count MBSSID elements, which can overflow if a user specifies 256 or more elements. This overflow can lead to a heap buffer overflow because num elems determines the size of the elems array, which is subsequently written to. The issue only affects devices where the wiphy->mbssid max interfaces member is set and can only be triggered by a process with CAP NET ADMIN capabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-04426
BDU:2026-04427
BDU:2026-04428
CESA-2022_1988
CVE-2023-53570
RHSA-2022:1988
RHSA-2022_1988
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse