
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53992 is a vulnerability in the Linux kernel's cfg80211 Wi-Fi subsystem related to improper handling of OCB (Outside the Context of a BSS) mode operations. Specifically, the code could attempt to instruct the driver or mac80211 to leave an OCB network even when no OCB state had been established (i.e., the device had not joined), leading to undefined or confusing behavior. The vulnerability was published on December 24, 2025, and affects Linux kernel versions prior to the fixes introduced in 6.1.55, 6.5.5, and 6.6. No CVSS score has been assigned by NVD at this time, and the EPSS score is approximately 0.017% (Feedly).
The root cause is improper state management in the cfg80211 OCB (Outside the Context of a BSS) handling code within the Linux kernel's wireless subsystem. When a leave operation is triggered without a prior join, the code incorrectly passes the request to the underlying driver or mac80211 layer, as no guard checks the chandef state to confirm an active OCB session exists. The fix introduces a simple check: if the chandef state is not set (indicating no active OCB join), the leave operation is skipped entirely. No CWE classification has been formally assigned by NVD. Patches are available via three kernel stable commits (kernel.org patch 1, kernel.org patch 2, kernel.org patch 3).
The primary impact of this vulnerability is the potential for undefined or erroneous behavior in the Linux kernel's wireless stack when an OCB leave operation is issued without a corresponding join. This could result in driver confusion, unexpected state corruption, or system instability in environments using OCB mode (commonly associated with vehicular/V2X communications). The vulnerability does not appear to directly enable remote code execution or privilege escalation based on available information, but improper driver interactions could contribute to denial-of-service conditions on affected wireless interfaces (Feedly).
The vulnerability is resolved in Linux kernel versions 6.1.55, 6.5.5, and 6.6 via upstream stable patches. Administrators should update to a patched kernel version as soon as possible. The fix is available in three stable commits: 94332210, abc76cf5, and d7b0fe34. SUSE has also issued advisories addressing this CVE as part of kernel update packages (Linux Security SUSE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."