CVE-2023-52594
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-52594 is an array-index-out-of-bounds read vulnerability discovered in the Linux kernel's ath9k_htc_txstatus() function within the WiFi driver. The vulnerability was disclosed on March 6, 2024, affecting multiple versions of the Linux kernel up to version 6.7.4. The issue specifically impacts the ath9k wireless driver component (NVD).

Technical details

The vulnerability occurs when txs->cnt, data from a URB provided by a USB device, is larger than the size of the array txs->txstatus, which is defined as HTC_MAX_TX_STATUS. While WARN_ON() checks for this condition, there was no proper bug handling code after the check. The issue was discovered using a modified version of the syzkaller fuzzing tool. The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (High) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD, Red Hat).

Impact

The vulnerability can lead to a system crash through an array-index-out-of-bounds read operation. When exploited, it could potentially cause a denial of service condition in the affected system (Red Hat).

Exploitability

The vulnerability requires local access with low privilege requirements and no user interaction for exploitation. The attack complexity is rated as low, making it relatively straightforward to exploit if an attacker has the necessary local access (NVD).

Mitigation and workarounds

A fix has been implemented that makes the function return if the problematic condition is detected. The patch has been integrated into various Linux kernel versions. System administrators should update their Linux kernel to the latest patched version (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68454HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 13, 2026
CVE-2026-68452HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-headers
NoYesAug 13, 2026
CVE-2026-68451HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-oracle-5.15
NoYesAug 13, 2026
CVE-2026-68453HIGH7.1
  • Linux Kernel logoLinux Kernel
  • kernel-uki-virt-addons
NoYesAug 13, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management