{"id":"DEBIAN-CVE-2023-53717","details":"In the Linux kernel, the following vulnerability has been resolved:  wifi: ath9k: Fix potential stack-out-of-bounds write in ath9k_wmi_rsp_callback()  Fix a stack-out-of-bounds write that occurs in a WMI response callback function that is called after a timeout occurs in ath9k_wmi_cmd(). The callback writes to wmi-\u003ecmd_rsp_buf, a stack-allocated buffer that could no longer be valid when a timeout occurs. Set wmi-\u003elast_seq_id to 0 when a timeout occurred.  Found by a modified version of syzkaller.  BUG: KASAN: stack-out-of-bounds in ath9k_wmi_ctrl_rx Write of size 4 Call Trace:  memcpy  ath9k_wmi_ctrl_rx  ath9k_htc_rx_msg  ath9k_hif_usb_reg_in_cb  __usb_hcd_giveback_urb  usb_hcd_giveback_urb  dummy_timer  call_timer_fn  run_timer_softirq  __do_softirq  irq_exit_rcu  sysvec_apic_timer_interrupt","modified":"2026-09-15T08:47:37.968013156Z","published":"2025-10-22T14:15:46.367Z","upstream":["CVE-2023-53717"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-53717"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53717.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53717.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-53717.json"}}],"schema_version":"1.9.0"}