Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: htc_hst: free skb in ath9k_htc_rx_msg() if there is no callback function It is stated that ath9k_htc_rx_msg() either frees the provided skb or passes its management to another callback function. However, the skb is not freed in case there is no another callback function, and Syzkaller was able to cause a memory leak. Also minor comment fix. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
References (8)
Core 8
Core References
Scores
EPSS
0.0018
EPSS Percentile
7.2%
Details
Status
published
Products (25)
linux/Kernel
2.6.35 - 4.14.308linux
linux/Kernel
4.15.0 - 4.19.276linux
linux/Kernel
4.20.0 - 5.4.235linux
linux/Kernel
5.11.0 - 5.15.99linux
linux/Kernel
5.16.0 - 6.1.16linux
linux/Kernel
5.5.0 - 5.10.173linux
linux/Kernel
6.2.0 - 6.2.3linux
Linux/Linux
< 2.6.35
Linux/Linux
2.6.35
Linux/Linux
4.14.308 - 4.14.*
... and 15 more
Published
Dec 09, 2025
Tracked Since
Feb 18, 2026