CVE-2023-52776
MEDIUMLinux Kernel 6.3-6.5.12 - Use-After-Free in ath12k DFS-Radar and Temperature Event Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dfs-radar and temperature event locking The ath12k active pdevs are protected by RCU but the DFS-radar and temperature event handling code calling ath12k_mac_get_ar_by_pdev_id() was not marked as a read-side critical section. Mark the code in question as RCU read-side critical sections to avoid any potential use-after-free issues. Note that the temperature event handler looks like a place holder currently but would still trigger an RCU lockdep splat. Compile tested only.
References (3)
Core 3
Scores
CVSS v3
5.9
EPSS
0.0071
EPSS Percentile
48.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (9)
Linux/Linux
< 6.3
Linux/Linux
6.3
Linux/Linux
6.5.13 - 6.5.*
Linux/Linux
6.6.3 - 6.6.*
Linux/Linux
6.7
Linux/Linux
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - 69bd216e049349886405b1c87a55dce3d35d1ba7
Linux/Linux
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - 774de37c147fea81f2c2e4be5082304f4f71d535
Linux/Linux
d889913205cf7ebda905b1e62c5867ed4e39f6c2 - d7a5f7f76568e48869916d769e28b9f3ca70c78e
linux/linux_kernel
6.3 - 6.5.13
Published
May 21, 2024
Tracked Since
Feb 18, 2026