
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53574 is a vulnerability in the Linux kernel's rtw88 WiFi driver, discovered and disclosed on October 4, 2025. The vulnerability affects various Linux distributions and their kernel versions, particularly impacting systems using the rtw88 wireless driver (NVD, Ubuntu).
The vulnerability involves a potential crash and memory leak condition in the rtw88 WiFi driver during driver unload operations. The issue occurs specifically when unloading or unbinding the driver, where a pending TX-purge timer and non-purged queues could continue to run after their associated structures were freed, leading to Use-After-Free (UAF) conditions and potential system crashes. The vulnerability has been assigned a CVSS v3.1 base score with vector AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H, indicating local access requirements and high privileges needed for exploitation (Red Hat).
The vulnerability's impact is primarily focused on system stability and reliability. When exploited, it can cause system crashes and memory leaks during the WiFi driver unload process. The issue requires local access and elevated privileges to exploit, which somewhat limits its potential impact (Red Hat).
The vulnerability has been resolved in the Linux kernel through fixes that properly handle the deletion of TX purge timer and freeing of SKB queue when unloading. The fix includes deleting the TX purge timer and freeing C2H queue in 'rtwcoredeinit()', as well as shrinking the critical section by freeing COEX queue out of TX report lock scope (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."