{"id":"DEBIAN-CVE-2023-54131","details":"In the Linux kernel, the following vulnerability has been resolved:  wifi: rt2x00: Fix memory leak when handling surveys  When removing a rt2x00 device, its associated channel surveys are not freed, causing a memory leak observable with kmemleak:  unreferenced object 0xffff9620f0881a00 (size 512):   comm \"systemd-udevd\", pid 2290, jiffies 4294906974 (age 33.768s)   hex dump (first 32 bytes):     70 44 12 00 00 00 00 00 92 8a 00 00 00 00 00 00  pD..............     00 00 00 00 00 00 00 00 ab 87 01 00 00 00 00 00  ................   backtrace:     [\u003cffffffffb0ed858b\u003e] __kmalloc+0x4b/0x130     [\u003cffffffffc1b0f29b\u003e] rt2800_probe_hw+0xc2b/0x1380 [rt2800lib]     [\u003cffffffffc1a9496e\u003e] rt2800usb_probe_hw+0xe/0x60 [rt2800usb]     [\u003cffffffffc1ae491a\u003e] rt2x00lib_probe_dev+0x21a/0x7d0 [rt2x00lib]     [\u003cffffffffc1b3b83e\u003e] rt2x00usb_probe+0x1be/0x980 [rt2x00usb]     [\u003cffffffffc05981e2\u003e] usb_probe_interface+0xe2/0x310 [usbcore]     [\u003cffffffffb13be2d5\u003e] really_probe+0x1a5/0x410     [\u003cffffffffb13be5c8\u003e] __driver_probe_device+0x78/0x180     [\u003cffffffffb13be6fe\u003e] driver_probe_device+0x1e/0x90     [\u003cffffffffb13be972\u003e] __driver_attach+0xd2/0x1c0     [\u003cffffffffb13bbc57\u003e] bus_for_each_dev+0x77/0xd0     [\u003cffffffffb13bd2a2\u003e] bus_add_driver+0x112/0x210     [\u003cffffffffb13bfc6c\u003e] driver_register+0x5c/0x120     [\u003cffffffffc0596ae8\u003e] usb_register_driver+0x88/0x150 [usbcore]     [\u003cffffffffb0c011c4\u003e] do_one_initcall+0x44/0x220     [\u003cffffffffb0d6134c\u003e] do_init_module+0x4c/0x220  Fix this by freeing the channel surveys on device removal.  Tested with a RT3070 based USB wireless adapter.","modified":"2026-09-15T08:47:27.151190220Z","published":"2025-12-24T13:16:15.087Z","upstream":["CVE-2023-54131"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54131"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.37-1"}]}],"versions":["6.1.27-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54131.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54131.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.3.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54131.json"}}],"schema_version":"1.9.0"}