CVE-2023-53226: wifi: mwifiex: Fix OOB and integer underflow when rx packets

Published Sep 15, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: Fix OOB and integer underflow when rx packets

Make sure mwifiexprocessmgmtpacket, mwifiexprocessstarxpacket and mwifiexprocessuaprxpacket, mwifiexuapqueuebridgedpkt and mwifiexprocessrxpacket not out-of-bounds access the skb->data buffer.

Other sources

In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: Fix OOB and integer underflow when rx packets

Make sure mwifiexprocessmgmtpacket, mwifiexprocessstarxpacket and mwifiexprocessuaprxpacket, mwifiexuapqueuebridgedpkt and mwifiexprocessrxpacket not out-of-bounds access the skb-data buffer.

IBM

Affected Software

10 affected components
Linux Kernel
Linux Linux kernel>=3.7<4.14.326
Linux Linux kernel>=4.15<4.19.295
Linux Linux kernel>=4.20<5.4.257
Linux Linux kernel>=5.5<5.10.195
Linux Linux kernel>=5.11<5.15.132
Linux Linux kernel>=5.16<6.1.53
Linux Linux kernel>=6.2<6.4.16
Linux Linux kernel>=6.5<6.5.3
IBM Cloud Pak for Data System<=11.3.0.2-IF1

Event History

Sep 15, 2025
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
DescriptionSeverity
Data Sourced
via Red Hat·03:12 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 28, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2023-53226?

CVE-2023-53226 is classified as a medium severity vulnerability affecting the Linux kernel series.

2

How do I fix CVE-2023-53226?

To mitigate CVE-2023-53226, you should upgrade to the latest stable version of the Linux kernel that has addressed this vulnerability.

3

What are the affected Linux kernel versions for CVE-2023-53226?

CVE-2023-53226 affects multiple versions of the Linux kernel, particularly those from 3.7 up to recent versions before the fix is applied.

4

What types of attacks does CVE-2023-53226 allow for?

CVE-2023-53226 can lead to out-of-bounds access and potential remote code execution through malformed WiFi packets.

5

Is CVE-2023-53226 remotely exploitable?

Yes, CVE-2023-53226 can be remotely exploitable via malicious WiFi packets targeting vulnerable systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203