Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-53785— mt76: mt7921: don't assume adequate headroom for SDIO headers

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于SDIO头部的缓冲区溢出问题。

CVSS 8.8 · High EPSS 0.27% · P19

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux e0f9fdda81bd32371ddac9222487e612027d8de2< 5c8bbb79c7cbca65534badf360f3b1145759c7bc affected
e0f9fdda81bd32371ddac9222487e612027d8de2< 414c0c04703423b78bc9dea1aa6493334dc61f6e affected
e0f9fdda81bd32371ddac9222487e612027d8de2< 98c4d0abf5c478db1ad126ff0c187dbb84c0803c affected
5.12 affected
< 5.12 unaffected
6.1.55≤ 6.1.* unaffected
6.5.5≤ 6.5.* unaffected
6.6≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-53785

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mt76: mt7921: don't assume adequate headroom for SDIO headers
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: don't assume adequate headroom for SDIO headers mt7921_usb_sdio_tx_prepare_skb() calls mt7921_usb_sdio_write_txwi() and mt7921_skb_add_usb_sdio_hdr(), both of which blindly assume that adequate headroom will be available in the passed skb. This assumption typically is satisfied when the skb was allocated in the net core for transmission via the mt7921 netdev (although even that is only an optimization and is not strictly guaranteed), but the assumption is sometimes not satisfied when the skb originated in the receive path of another netdev and was passed through to the mt7921, such as by the bridge layer. Blindly prepending bytes to an skb is always wrong. This commit introduces a call to skb_cow_head() before the call to mt7921_usb_sdio_write_txwi() in mt7921_usb_sdio_tx_prepare_skb() to ensure that at least MT_SDIO_TXD_SIZE + MT_SDIO_HDR_SIZE bytes can be pushed onto the skb. Without this fix, I can trivially cause kernel panics by bridging an MT7921AU-based USB 802.11ax interface with an Ethernet interface on an Intel Atom-based x86 system using its onboard RTL8169 PCI Ethernet adapter and also on an ARM-based Raspberry Pi 1 using its onboard SMSC9512 USB Ethernet adapter. Note that the panics do not occur in every system configuration, as they occur only if the receiving netdev leaves less headroom in its received skbs than the mt7921 needs for its SDIO headers. Here is an example stack trace of this panic on Raspberry Pi OS Lite 2023-02-21 running kernel 6.1.24+ [1]: skb_panic from skb_push+0x44/0x48 skb_push from mt7921_usb_sdio_tx_prepare_skb+0xd4/0x190 [mt7921_common] mt7921_usb_sdio_tx_prepare_skb [mt7921_common] from mt76u_tx_queue_skb+0x94/0x1d0 [mt76_usb] mt76u_tx_queue_skb [mt76_usb] from __mt76_tx_queue_skb+0x4c/0xc8 [mt76] __mt76_tx_queue_skb [mt76] from mt76_txq_schedule.part.0+0x13c/0x398 [mt76] mt76_txq_schedule.part.0 [mt76] from mt76_txq_schedule_all+0x24/0x30 [mt76] mt76_txq_schedule_all [mt76] from mt7921_tx_worker+0x58/0xf4 [mt7921_common] mt7921_tx_worker [mt7921_common] from __mt76_worker_fn+0x9c/0xec [mt76] __mt76_worker_fn [mt76] from kthread+0xbc/0xe0 kthread from ret_from_fork+0x14/0x34 After this fix, bridging the mt7921 interface works fine on both of my previously problematic systems. [1] https://github.com/raspberrypi/firmware/tree/5c276f55a4b21345cd4d6200a504ee991851ff7a
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于SDIO头部的缓冲区溢出问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux e0f9fdda81bd32371ddac9222487e612027d8de2 ~ 5c8bbb79c7cbca65534badf360f3b1145759c7bc -
Linux Linux 5.12 -

II. Public POCs for CVE-2023-53785

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-53785

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-09 · 152 CVEs total

CVE-2025-40343 9.8 CRITICAL nvmet-fc: avoid scheduling association deletion twice
CVE-2022-50666 9.8 CRITICAL RDMA/siw: Fix QP destroy to wait for all references dropped.
CVE-2023-53794 9.8 CRITICAL cifs: fix session state check in reconnect to avoid use-after-free issue
CVE-2025-40342 8.8 HIGH nvme-fc: use lock accessing port_state and rport state
CVE-2023-53822 8.8 HIGH wifi: ath11k: Ignore frags from uninitialized peer in dp.
CVE-2025-40336 8.8 HIGH drm/gpusvm: fix hmm_pfn_to_map_order() usage
CVE-2023-53827 8.8 HIGH Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
CVE-2025-40328 8.8 HIGH smb: client: fix potential UAF in smb2_close_cached_fid()
CVE-2023-53851 8.4 HIGH drm/msm/dp: Drop aux devices together with DP controller
CVE-2025-40337 8.2 HIGH net: stmmac: Correctly handle Rx checksum offload errors
CVE-2022-50656 8.1 HIGH nfc: pn533: Clear nfc_target before being used
CVE-2023-53803 8.1 HIGH scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process()
CVE-2023-53790 7.8 HIGH bpf: Zeroing allocated object from slab in bpf memory allocator
CVE-2023-53862 7.8 HIGH hfs: fix missing hfs_bnode_get() in __hfs_bnode_create
CVE-2023-53781 7.8 HIGH smc: Fix use-after-free in tcp_write_timer_handler().
CVE-2023-53806 7.8 HIGH drm/amd/display: populate subvp cmd info only for the top pipe
CVE-2023-53860 7.8 HIGH dm: don't attempt to queue IO under RCU protection
CVE-2023-53795 7.8 HIGH iommufd: IOMMUFD_DESTROY should not increase the refcount
CVE-2023-53800 7.8 HIGH ubi: Fix use-after-free when volume resizing failed
CVE-2023-53836 7.8 HIGH bpf, sockmap: Fix skb refcnt race after locking changes

Showing top 20 of 152 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-53785

No comments yet


Leave a comment