{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-53679","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-10-07T15:16:59.664Z","datePublished":"2025-10-07T15:21:33.926Z","dateUpdated":"2026-08-05T09:15:30.817Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T09:15:30.817Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt7601u: fix an integer underflow\n\nFix an integer underflow that leads to a null pointer dereference in\n'mt7601u_rx_skb_from_seg()'. The variable 'dma_len' in the URB packet\ncould be manipulated, which could trigger an integer underflow of\n'seg_len' in 'mt7601u_rx_process_seg()'. This underflow subsequently\ncauses the 'bad_frame' checks in 'mt7601u_rx_skb_from_seg()' to be\nbypassed, eventually leading to a dereference of the pointer 'p', which\nis a null pointer.\n\nEnsure that 'dma_len' is greater than 'min_seg_len'.\n\nFound by a modified version of syzkaller.\n\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 PID: 12 Comm: ksoftirqd/0 Tainted: G        W  O      5.14.0+\n#139\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\nrel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014\nRIP: 0010:skb_add_rx_frag+0x143/0x370\nCode: e2 07 83 c2 03 38 ca 7c 08 84 c9 0f 85 86 01 00 00 4c 8d 7d 08 44\n89 68 08 48 b8 00 00 00 00 00 fc ff df 4c 89 fa 48 c1 ea 03 <80> 3c 02\n00 0f 85 cd 01 00 00 48 8b 45 08 a8 01 0f 85 3d 01 00 00\nRSP: 0018:ffffc900000cfc90 EFLAGS: 00010202\nRAX: dffffc0000000000 RBX: ffff888115520dc0 RCX: 0000000000000000\nRDX: 0000000000000001 RSI: ffff8881118430c0 RDI: ffff8881118430f8\nRBP: 0000000000000000 R08: 0000000000000e09 R09: 0000000000000010\nR10: ffff888111843017 R11: ffffed1022308602 R12: 0000000000000000\nR13: 0000000000000e09 R14: 0000000000000010 R15: 0000000000000008\nFS:  0000000000000000(0000) GS:ffff88811a800000(0000)\nknlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000004035af40 CR3: 00000001157f2000 CR4: 0000000000750ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n mt7601u_rx_tasklet+0xc73/0x1270\n ? mt7601u_submit_rx_buf.isra.0+0x510/0x510\n ? tasklet_action_common.isra.0+0x79/0x2f0\n tasklet_action_common.isra.0+0x206/0x2f0\n __do_softirq+0x1b5/0x880\n ? tasklet_unlock+0x30/0x30\n run_ksoftirqd+0x26/0x50\n smpboot_thread_fn+0x34f/0x7d0\n ? smpboot_register_percpu_thread+0x370/0x370\n kthread+0x3a1/0x480\n ? set_kthread_struct+0x120/0x120\n ret_from_fork+0x1f/0x30\nModules linked in: 88XXau(O) 88x2bu(O)\n---[ end trace 57f34f93b4da0f9b ]---\nRIP: 0010:skb_add_rx_frag+0x143/0x370\nCode: e2 07 83 c2 03 38 ca 7c 08 84 c9 0f 85 86 01 00 00 4c 8d 7d 08 44\n89 68 08 48 b8 00 00 00 00 00 fc ff df 4c 89 fa 48 c1 ea 03 <80> 3c 02\n00 0f 85 cd 01 00 00 48 8b 45 08 a8 01 0f 85 3d 01 00 00\nRSP: 0018:ffffc900000cfc90 EFLAGS: 00010202\nRAX: dffffc0000000000 RBX: ffff888115520dc0 RCX: 0000000000000000\nRDX: 0000000000000001 RSI: ffff8881118430c0 RDI: ffff8881118430f8\nRBP: 0000000000000000 R08: 0000000000000e09 R09: 0000000000000010\nR10: ffff888111843017 R11: ffffed1022308602 R12: 0000000000000000\nR13: 0000000000000e09 R14: 0000000000000010 R15: 0000000000000008\nFS:  0000000000000000(0000) GS:ffff88811a800000(0000)\nknlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000004035af40 CR3: 00000001157f2000 CR4: 0000000000750ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","baseScore":8.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The mt7601u is an 802.11 USB dongle and the vulnerable code is its RX completion tasklet, which parses frame descriptors fed by an untrusted external wireless adapter within radio range of the victim; this is the WiFi-frame-reception path, not a local syscall interface. This matches the CNA's treatment of equivalent USB-attached network device RX-framing bugs (CVE-2026-64540 gl620a, CVE-2026-64547 net1080, CVE-2025-37918 btusb) as Adjacent.\nAC:L - The trigger is a single malformed length field (`dma_len` < 40) in a received segment; there is no race, no timing window, and no dependence on memory layout the attacker cannot influence, and it can be replayed indefinitely for a deterministic underflow.\nPR:N - `mt7601u_rx_process_entry()` runs in softirq context on every RX URB as soon as the interface is up, before mac80211 performs any authentication, association, or decryption validation, so no credentials or local account are required.\nUI:N - Frame processing is fully automatic in the RX tasklet; no victim action such as connecting to a network, mounting, or opening a file is needed.\nS:U - The underflow, the NULL dereference, and the out-of-bounds fragment all occur within the kernel's own security authority with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - With the length guard defeated, `skb_add_rx_frag()` attaches up to ~4 KB starting beyond the received data — past the end of the 32 KB RX page when the crafted segment is near the buffer tail — and that adjacent kernel memory is delivered up the mac80211/network stack as frame payload, an unbounded heap disclosure.\nI:L - There is no out-of-bounds write primitive (the linear copies stay within the skb's tailroom), but the driver builds an skb whose fragment descriptor points outside the valid buffer with a `truesize` of 12 for a multi-kilobyte fragment, corrupting skb memory accounting and injecting attacker-influenced kernel memory as a frame into the stack.\nA:H - The documented result is a KASAN-confirmed NULL pointer dereference at `skb_add_rx_frag+0x143` inside `mt7601u_rx_tasklet`, i.e. a kernel oops in softirq context, repeatable on every malformed segment."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt7601u/dma.c"],"versions":[{"version":"c869f77d6abb5d5f9f2f1a661d5c53862a9cad34","lessThan":"67e4519afba215199b6dfa39ce5d7ea673ee4138","status":"affected","versionType":"git"},{"version":"c869f77d6abb5d5f9f2f1a661d5c53862a9cad34","lessThan":"47dc1f425af57b71111d7b01ebd24e04e8d967ef","status":"affected","versionType":"git"},{"version":"c869f77d6abb5d5f9f2f1a661d5c53862a9cad34","lessThan":"1a1f43059afae5cc9409e0c3bc63bfc09bc8facb","status":"affected","versionType":"git"},{"version":"c869f77d6abb5d5f9f2f1a661d5c53862a9cad34","lessThan":"61d0163e2be7a439cf6f82e9ad7de563ecf41e7a","status":"affected","versionType":"git"},{"version":"c869f77d6abb5d5f9f2f1a661d5c53862a9cad34","lessThan":"d0db59e2f718d1e2f1d2a2d8092168fdd2f3add0","status":"affected","versionType":"git"},{"version":"c869f77d6abb5d5f9f2f1a661d5c53862a9cad34","lessThan":"803f3176c5df3b5582c27ea690f204abb60b19b9","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/wireless/mediatek/mt7601u/dma.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"5.4.235","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.173","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.99","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.16","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2.3","lessThanOrEqual":"6.2.*","status":"unaffected","versionType":"semver"},{"version":"6.3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.4.235"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.10.173"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.15.99"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.1.16"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.2.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/67e4519afba215199b6dfa39ce5d7ea673ee4138"},{"url":"https://git.kernel.org/stable/c/47dc1f425af57b71111d7b01ebd24e04e8d967ef"},{"url":"https://git.kernel.org/stable/c/1a1f43059afae5cc9409e0c3bc63bfc09bc8facb"},{"url":"https://git.kernel.org/stable/c/61d0163e2be7a439cf6f82e9ad7de563ecf41e7a"},{"url":"https://git.kernel.org/stable/c/d0db59e2f718d1e2f1d2a2d8092168fdd2f3add0"},{"url":"https://git.kernel.org/stable/c/803f3176c5df3b5582c27ea690f204abb60b19b9"}],"title":"wifi: mt7601u: fix an integer underflow","x_generator":{"engine":"bippy-1.2.0"}}}}