CVE-2023-52768: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: use vmm_table as array in wilc struct Enabling KASAN and running some iperf tests raises some memory issues with vmm_table: BUG: KASAN: slab-out-of-bounds in wilc_wlan_handle_txq+0x6ac/0xdb4 Write of size 4 at addr c3a61540 by task wlan0-tx/95 KASAN detects that we are writing data beyond range allocated to vmm_table. There is indeed a mismatch between the size passed to allocator in wilc_wlan_init, and the range of possible indexes used later: allocation size is missing a multiplication by sizeof(u32)

Affected products

  • Linux Linux Kernel: from 5.15.68, before 5.15.140 (fixed in 5.15.140); from 5.19.9, before 6.1.64 (fixed in 6.1.64); from 6.2, before 6.5.13 (fixed in 6.5.13); from 6.6, before 6.6.3 (fixed in 6.6.3)

Published 2024-05-21. Last modified 2026-08-04.