CVE-2023-54036
Last modified
CVE-2023-54036 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: Fix memory leaks with RTL8723BU, RTL8192EU The wifi + bluetooth combo chip RTL8723BU can leak memory (especially?) when it's connected to a bluetooth audio device. The busy bluetooth traffic generates lots of C2H (card to host) messages, which are not freed correctly. To fix this, move the dev_kfree_skb() call in rtl8xxxu_c2hcmd_callback() inside the loop where skb_dequeue() is called. The RTL8192EU leaks memory because the C2H messages are added to the queue and left there forever. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: Fix memory leaks with RTL8723BU, RTL8192EU The wifi + bluetooth combo chip RTL8723BU can leak memory (especially?) when it's connected to a bluetooth audio device. The busy bluetooth traffic generates lots of C2H (card to host) messages, which are not freed correctly. To fix this, move the dev_kfree_skb() call in rtl8xxxu_c2hcmd_callback() inside the loop where skb_dequeue() is called. The RTL8192EU leaks memory because the C2H messages are added to the queue and left there forever. (This was fine in the past because it probably wasn't sending any C2H messages until commit e542e66b7c2e ("wifi: rtl8xxxu: gen2: Turn on the rate control"). Since that commit it sends a C2H message when the TX rate changes.) To fix this, delete the check for rf_paths > 1 and the goto. Let the function process the C2H messages from RTL8192EU like the ones from the other chips. Theoretically the RTL8188FU could also leak like RTL8723BU, but it most likely doesn't send C2H messages frequently enough. This change was tested with RTL8723BU by Erhard F. I tested it with RTL8188FU and RTL8192EU.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= e542e66b7c2ee2adeefdbb7f259f2f60cadf2819, < 430f9f9bec53a75f9ccc53e156a66f13fc098b83; >= e542e66b7c2ee2adeefdbb7f259f2f60cadf2819, < 35fb0e275af1aa1ca0a9784417e90f988aaf8e78; >= e542e66b7c2ee2adeefdbb7f259f2f60cadf2819, < 93c3f34ec02fc81188d328287d4fddd498ccddea; >= e542e66b7c2ee2adeefdbb7f259f2f60cadf2819, < f39a86b4efd270947ee252cc32a30b0aef492d65; >= e542e66b7c2ee2adeefdbb7f259f2f60cadf2819, < b39f662ce1648db0b9de32e6a849b098480793cb |
| Linux | Linux | 5.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54036?
How severe is CVE-2023-54036?
How do I fix CVE-2023-54036?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-54030In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54031In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54032In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54033In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54034In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54035In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54037In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54038In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54039In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5404Server receiving a malformed message can cause a pointer to …8.1
- CVE-2023-54040In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2023-54041In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2023-54036?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
