GHSA-wf4x-cm6m-6wpw · Severity: unknown — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix memory...
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix memory leaks in beacon template setup The functions ath11k_mac_setup_bcn_tmpl_ema() and ath11k_mac_setup_bcn_tmpl_mbssid() allocate memory for beacon templates but fail to free it when parameter setup returns an error. Since beacon templates must be released during normal execution, they must also be released in the error handling paths to prevent memory leaks. Fix this by using unified exit paths with proper cleanup in the respective error paths. Compile tested only. Issue found using a prototype static analysis tool and code review.
Conclusion & alert: CVE-2026-53113 is rated Low Risk (5.4/100): low exploitation likelihood (EPSS 0.16%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-25 | — | 0.16% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
No CVSS data in dataset for this CVE.
GHSA-wf4x-cm6m-6wpw · Severity: unknown — In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix memory...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2026-53113 unimportant priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1. | https://security-tracker.debian.org/tracker/CVE-2026-53113 |
suse
|
medium | CVE-2026-53113 severity moderate: SUSE including 20 source package names (cluster-md-kmp-default, dlm-kmp-default, …), 140 product×package rows across 28 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, … (28 product lines)): Known Not Affected 140. | https://www.suse.com/security/cve/CVE-2026-53113/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linux | linux_kernel | >= 6.5, < 7.0.10 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 6.5, < 7.1 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |