CVE-2023-54229
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54229 is a vulnerability in the Linux kernel's ath11k WiFi driver that causes a 6GHz-only PHY (physical layer) to fail registration when the Board Data File (BDF) does not include support for the 7115MHz channel. The root cause is described as a typo in the driver code, which triggers a kernel warning in wiphy_register and causes IEEE 802.11 registration to fail with error code -22. It affects the Linux kernel and was published on December 30, 2025. It carries a CVSS v3.1 base score of 7.0 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The vulnerability (CWE classification not formally assigned, but related to improper input/channel range validation) stems from a typo in the ath11k WiFi driver's 6GHz PHY registration logic. When a 6GHz-only PHY is initialized and the BDF does not permit the 7115MHz channel, the flawed condition causes wiphy_register to fail, triggering a kernel WARNING at net/wireless/core.c:907 and ultimately returning error -22 (EINVAL) from ieee80211_register_hw. The call trace involves ath11k_mac_registerath11k_core_qmi_firmware_readyath11k_qmi_driver_event_work, indicating the failure occurs during firmware initialization in a kernel workqueue context. Exploitation requires local access with low privileges and high attack complexity (Red Hat Bugzilla, Red Hat Advisory).

Impact

Successful exploitation renders the 6GHz-only WiFi hardware non-functional by preventing proper initialization and registration with the kernel's mac80211 subsystem. According to the CVSS scoring, the vulnerability can result in high impacts to confidentiality, integrity, and availability on the affected system. The primary practical impact is denial of wireless service on affected hardware configurations, though the CVSS score also reflects potential for broader kernel-level compromise by a local low-privileged attacker (Red Hat Advisory, Red Hat Bugzilla).

Mitigation and workarounds

A patch has been made available in the Linux kernel addressing the typo in the ath11k driver's 6GHz PHY registration logic. Administrators should update to a patched version of the Linux kernel that includes the fix (referenced in upstream commits at git.kernel.org). Systems utilizing 6GHz-only WiFi hardware (e.g., devices using ath11k_pci with BDFs lacking 7115MHz channel support) should be prioritized for patching. Red Hat has tracked this issue in Bugzilla and the upstream advisory is available via the Linux CVE announcement list (Red Hat Bugzilla, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management