wifi: cfg80211: reject auth/assoc to AP with our address
Summary
| CVE | CVE-2023-53540 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-04 16:15:49 UTC |
| Updated | 2026-04-06 13:32:53 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject auth/assoc to AP with our address If the AP uses our own address as its MLD address or BSSID, then clearly something's wrong. Reject such connections so we don't try and fail later. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: NVD-CWE-noinfo
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 19957bb399e2722719c0e20c9ae91cf8b6aaff04 676a423410131d111a264d29aecbe6aadd57fb22 git | Not specified |
| CNA | Linux | Linux | affected 19957bb399e2722719c0e20c9ae91cf8b6aaff04 07added2c6cd63de047bc786b39436322abb67c0 git | Not specified |
| CNA | Linux | Linux | affected 19957bb399e2722719c0e20c9ae91cf8b6aaff04 5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 git | Not specified |
| CNA | Linux | Linux | affected 2.6.32 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.32 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.55 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.5.5 6.5.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/07added2c6cd63de047bc786b39436322abb67c0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/5d4e04bf3a0f098bd9033de3a5291810fa14c7a6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/676a423410131d111a264d29aecbe6aadd57fb22 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.