CVE-2023-54052
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54052 is a socket buffer (SKB) leak vulnerability in the Linux kernel's mt76/mt7921 Wi-Fi driver caused by missing transmission status (txs) handling when frames are aggregated in AMSDU. When txs packets are dropped during AMSDU aggregation, SKBs are held in the driver indefinitely, causing temporary network stalls. The vulnerability affects Linux kernel versions starting from commit 163f4d22c118d4eb9e275bf9ee1577c0d14b3208 up to the patched releases. It was published on December 24, 2025, and carries an estimated CVSS severity of Medium with an EPSS score of 0.000180 (Feedly, EUVD).

Technical details

The root cause is a resource management flaw (CWE-400 / uncontrolled resource consumption) in the mt7921 Wi-Fi driver within the Linux kernel's mt76 subsystem. When Wi-Fi frames are aggregated into an AMSDU, the driver may not receive the expected transmission status (txs) acknowledgment for each sub-frame, causing the associated SKBs to remain allocated and unreleased in the driver's internal queues. Although a txs timeout handler can eventually recover the held SKBs, the window of resource exhaustion is sufficient to temporarily halt network operations. The fix disables txs reporting for AMSDU-aggregated frames in the mt7921 driver to prevent the leak condition (Feedly, EUVD).

Impact

Exploitation of this vulnerability results in a temporary denial of network service on systems using the MediaTek mt7921 Wi-Fi chipset. Affected SKBs accumulate in the driver until the txs timeout handler reclaims them, during which network connectivity is interrupted. There is no evidence of confidentiality or integrity impact; the vulnerability is limited to availability of the wireless network interface (Feedly, EUVD).

Mitigation and workarounds

The Linux kernel maintainers have released fixes backported to multiple stable branches: kernel 6.1.52 (commit 1cd102aaedb2), 6.4.15 (commit e74778e91fed), 6.5.2 (commit bf5d3fad7219), and 6.6 (commit b642f4c5f3de). Users should update to a patched kernel version for their distribution. SUSE has issued advisories (SUSE-2026-0281-1 and SUSE-2026-20876-1) incorporating these fixes (Feedly, Linux Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management