PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53113 Linux CVE debrief

A memory leak vulnerability was found in the Linux kernel's wifi: ath11k beacon template setup. The functions ath11k_mac_setup_bcn_tmpl_ema() and ath11k_mac_setup_bcn_tmpl_mbssid() allocate memory for beacon templates but fail to free it when parameter setup returns an error. This can cause memory leaks if the setup fails. The affected product is the Linux kernel. The vulnerability class is a memory leak. The likely operational impact is system instability and performance issues. The source-confidence limits are based on the CVE record and NVD entry.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-09-07
Advisory published
2026-06-24
Advisory updated
2026-09-07

Who should care

Linux kernel maintainers, users, and administrators should assess exposure and apply patches to prevent potential memory leaks. The affected operator is the Linux kernel maintainer. The platform is Linux. The vulnerability-management impact is that patches should be applied to fix the memory leak vulnerability. The security-team impact is that they should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor 1

Why it matters

CVE-2026-53113 is a memory leak vulnerability in the Linux kernel's wifi: ath11k beacon template setup. Linux kernel maintainers and users should assess exposure and apply patches to prevent potential memory leaks. The CVSS score for this vulnerability is 5.5 (Medium).

  • Memory leaks can cause system instability and performance issues.
  • Successful exploitation requires local access and low privileges.
  • Verification of patch application is necessary to ensure fix.

Technical summary

The Linux kernel's wifi: ath11k beacon template setup has a memory leak vulnerability. The functions ath11k_mac_setup_bcn_tmpl_ema() and ath11k_mac_setup_bcn_tmpl_mbssid() allocate memory for beacon templates but fail to free it when parameter setup returns an error. This can cause memory leaks if the setup fails. The CVSS score for this vulnerability is 5.5 (Medium). The affected product context is the Linux kernel. The defensive impact is that Linux kernel maintainers and users should assess exposure and apply patches to prevent potential memory leaks.

Defensive priority

Medium priority for Linux kernel maintainers and users to assess exposure and apply patches.

Recommended defensive actions

  • Assess exposure by checking if the Linux kernel version is within the affected range (6.5 to 7.0.10).
  • Apply patches from Linux kernel maintainers to fix the memory leak vulnerability.
  • Monitor system logs for potential memory leak issues.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The Linux kernel maintainers have released patches to fix the issue. The evidence limits are based on the information provided by the CVE Program and NVD. Defenders should verify the patch application and review system logs for potential memory leak issues.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53113 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53113

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53113 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53113

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5d63aa38d5ca85206d9699ffdd616b58780dba07

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5fc3d921512d31839227a2d22a2990de02acefeb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9478aa5b39e986d45fafe279c24d3546783c22b1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ff49eba595df500e4ddccc593088c8a4ab5f2c27

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.