
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-54052 is a socket buffer (SKB) leak vulnerability in the Linux kernel's mt76/mt7921 Wi-Fi driver caused by missing transmission status (txs) handling when frames are aggregated in AMSDU. When txs packets are dropped during AMSDU aggregation, SKBs are held in the driver indefinitely, causing temporary network stalls. The vulnerability affects Linux kernel versions starting from commit 163f4d22c118d4eb9e275bf9ee1577c0d14b3208 up to the patched releases. It was published on December 24, 2025, and carries an estimated CVSS severity of Medium with an EPSS score of 0.000180 (Feedly, EUVD).
The root cause is a resource management flaw (CWE-400 / uncontrolled resource consumption) in the mt7921 Wi-Fi driver within the Linux kernel's mt76 subsystem. When Wi-Fi frames are aggregated into an AMSDU, the driver may not receive the expected transmission status (txs) acknowledgment for each sub-frame, causing the associated SKBs to remain allocated and unreleased in the driver's internal queues. Although a txs timeout handler can eventually recover the held SKBs, the window of resource exhaustion is sufficient to temporarily halt network operations. The fix disables txs reporting for AMSDU-aggregated frames in the mt7921 driver to prevent the leak condition (Feedly, EUVD).
Exploitation of this vulnerability results in a temporary denial of network service on systems using the MediaTek mt7921 Wi-Fi chipset. Affected SKBs accumulate in the driver until the txs timeout handler reclaims them, during which network connectivity is interrupted. There is no evidence of confidentiality or integrity impact; the vulnerability is limited to availability of the wireless network interface (Feedly, EUVD).
The Linux kernel maintainers have released fixes backported to multiple stable branches: kernel 6.1.52 (commit 1cd102aaedb2), 6.4.15 (commit e74778e91fed), 6.5.2 (commit bf5d3fad7219), and 6.6 (commit b642f4c5f3de). Users should update to a patched kernel version for their distribution. SUSE has issued advisories (SUSE-2026-0281-1 and SUSE-2026-20876-1) incorporating these fixes (Feedly, Linux Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."