Junglewise Threat Intelligence

CVE-2026-53113: Linux Kernel ath11k memory leak in beacon template setup

CVE-2026-53113 · Severity: info · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Qualcomm Wi-Fi driver (ath11k) could lead to memory leaks. This occurs when the system fails to properly release memory during certain Wi-Fi configuration errors. Over time, this could degrade system performance or lead to a crash, potentially impacting the availability of devices using this specific Wi-Fi hardware.

Technical details

A memory leak exists in the Linux kernel ath11k Wi-Fi driver within the functions ath11k_mac_setup_bcn_tmpl_ema() and ath11k_mac_setup_bcn_tmpl_mbssid(). These functions allocate memory for beacon templates but do not free the memory if a parameter setup error occurs. An attacker or specific system conditions triggering these error paths could cause kernel memory exhaustion. The issue was identified via static analysis and code review. It has been resolved by implementing unified exit paths that ensure memory is freed regardless of whether the setup succeeds or fails.

Affected products

  • Linux Linux Kernel 6.5 to 7.1

Timeline

  • 2026-01-30: other: Patch submitted by developer
  • 2026-05-23: patched: Patch committed to stable tree
  • 2026-06-24: disclosed: CVE published

References

Related threats