PT-2025-49645 · Mt7921+6 · Mt7921+6

Published

2023-07-25

·

Updated

2026-04-20

·

CVE-2023-53785

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the mt76 and mt7921 components related to SDIO header handling. Specifically, the mt7921 usb sdio tx prepare skb() function does not adequately ensure sufficient headroom in skb (socket buffer) structures when preparing data for transmission. This can lead to kernel panics when bridging an MT7921AU-based USB 802.11ax interface with an Ethernet interface, particularly on systems where the receiving network device leaves limited headroom in received skbs. The issue arises from blindly prepending bytes to an skb without verifying available space. The fix involves a call to skb cow head() to guarantee sufficient headroom for SDIO headers. Exploitation can be triggered by bridging the affected interface, and has been observed on Raspberry Pi OS Lite and Intel Atom-based systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2026-01270
CVE-2023-53785
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1

Affected Products

Debian
Intel Atom
Linux Kernel
Mt7921Au
Raspberry Pi Os Lite
Mt76
Mt7921