CVE-2023-53992
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53992 is a vulnerability in the Linux kernel's cfg80211 Wi-Fi subsystem related to improper handling of OCB (Outside the Context of a BSS) mode operations. Specifically, the code could attempt to instruct the driver or mac80211 to leave an OCB network even when no OCB state had been established (i.e., the device had not joined), leading to undefined or confusing behavior. The vulnerability was published on December 24, 2025, and affects Linux kernel versions prior to the fixes introduced in 6.1.55, 6.5.5, and 6.6. No CVSS score has been assigned by NVD at this time, and the EPSS score is approximately 0.017% (Feedly).

Technical details

The root cause is improper state management in the cfg80211 OCB (Outside the Context of a BSS) handling code within the Linux kernel's wireless subsystem. When a leave operation is triggered without a prior join, the code incorrectly passes the request to the underlying driver or mac80211 layer, as no guard checks the chandef state to confirm an active OCB session exists. The fix introduces a simple check: if the chandef state is not set (indicating no active OCB join), the leave operation is skipped entirely. No CWE classification has been formally assigned by NVD. Patches are available via three kernel stable commits (kernel.org patch 1, kernel.org patch 2, kernel.org patch 3).

Impact

The primary impact of this vulnerability is the potential for undefined or erroneous behavior in the Linux kernel's wireless stack when an OCB leave operation is issued without a corresponding join. This could result in driver confusion, unexpected state corruption, or system instability in environments using OCB mode (commonly associated with vehicular/V2X communications). The vulnerability does not appear to directly enable remote code execution or privilege escalation based on available information, but improper driver interactions could contribute to denial-of-service conditions on affected wireless interfaces (Feedly).

Mitigation and workarounds

The vulnerability is resolved in Linux kernel versions 6.1.55, 6.5.5, and 6.6 via upstream stable patches. Administrators should update to a patched kernel version as soon as possible. The fix is available in three stable commits: 94332210, abc76cf5, and d7b0fe34. SUSE has also issued advisories addressing this CVE as part of kernel update packages (Linux Security SUSE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64192HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-oracle-5.4
NoYesJul 20, 2026
CVE-2026-64191HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-ibm
NoYesJul 20, 2026
CVE-2026-64600HIGH7.1
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-devel
NoYesJul 23, 2026
CVE-2026-64206MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesJul 20, 2026
CVE-2026-64205MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-modules
NoNoJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management