
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53422 was discovered and published on September 18, 2025, affecting the Linux kernel's iwlwifi firmware component. The vulnerability involves a memory leak in the debugfs functionality when reading the fw_info file (NVD).
The vulnerability occurs specifically in the iwlwifi firmware component of the Linux kernel, where a memory leak is triggered when reading the fw_info file to completion. The issue arises because the system returns NULL to indicate no more data is available, but fails to free the status tracking object (NVD).
The vulnerability results in a memory leak condition in the Linux kernel's wifi subsystem. While the immediate impact is resource consumption through memory leaks, this could potentially lead to system performance degradation over time (Ubuntu).
Multiple Linux distributions have released patches to address this vulnerability. Ubuntu has fixed this in version 5.15.0-79.86~20.04.2 for linux-hwe-5.15, and similar fixes have been implemented in other kernel versions. Red Hat and other distributions have also provided updates to address this issue (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."