Use-after-free in Linux kernel - CVE-2023-52776
Published: May 31, 2024 / Updated: May 14, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ath12k_wmi_pdev_dfs_radar_detected_event() and ath12k_wmi_pdev_temperature_event() functions in drivers/net/wireless/ath/ath12k/wmi.c. A local user can escalate privileges on the system.
Remediation
External links
- https://git.kernel.org/stable/c/774de37c147fea81f2c2e4be5082304f4f71d535
- https://git.kernel.org/stable/c/d7a5f7f76568e48869916d769e28b9f3ca70c78e
- https://git.kernel.org/stable/c/69bd216e049349886405b1c87a55dce3d35d1ba7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.7