cbcvebase.
CVE-2023-53182
published 2025-09-15

CVE-2023-53182: In the Linux kernel, the following vulnerability has been resolved: ACPICA: Avoid undefined behavior: applying zero offset to null pointer ACPICA commit…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ACPICA: Avoid undefined behavior: applying zero offset to null pointer ACPICA commit 770653e3ba67c30a629ca7d12e352d83c2541b1e Before this change we see the following UBSAN stack trace in Fuchsia: #0 0x000021e4213b3302 in acpi_ds_init_aml_walk(struct acpi_walk_state*, union acpi_parse_object*, struct acpi_namespace_node*, u8*, u32, struct acpi_evaluate_info*, u8) ../../third_party/acpica/source/components/dispatcher/dswstate.c:682 +0x233302 #1.2 0x000020d0f660777f in ubsan_get_stack_trace() compiler-rt/lib/ubsan/ubsan_diag.cpp:41 +0x3d77f #1.1 0x000020d0f660777f in maybe_print_stack_trace() compiler-rt/lib/ubsan/ubsan_diag.cpp:51 +0x3d77f #1 0x000020d0f660777f in ~scoped_report() compiler-rt/lib/ubsan/ubsan_diag.cpp:387 +0x3d77f #2 0x000020d0f660b96d in handlepointer_overflow_impl() compiler-rt/lib/ubsan/ubsan_handlers.cpp:809 +0x4196d #3 0x000020d0f660b50d in compiler-rt/lib/ubsan/ubsan_handlers.cpp:815 +0x4150d #4 0x000021e4213b3302 in acpi_ds_init_aml_walk(struct acpi_walk_state*, union acpi_parse_object*, struct acpi_namespace_node*, u8*, u32, struct acpi_evaluate_info*, u8) ../../third_party/acpica/source/components/dispatcher/dswstate.c:682 +0x233302 #5 0x000021e4213e2369 in acpi_ds_call_control_method(struct acpi_thread_state*, struct acpi_walk_state*, union acpi_parse_object*) ../../third_party/acpica/source/components/dispatcher/dsmethod.c:605 +0x262369 #6 0x000021e421437fac in acpi_ps_parse_aml(struct acpi_walk_state*) ../../third_party/acpica/source/components/parser/psparse.c:550 +0x2b7fac #7 0x000021e4214464d2 in acpi_ps_execute_method(struct acpi_evaluate_info*) ../../third_party/acpica/source/components/parser/psxface.c:244 +0x2c64d2 #8 0x000021e4213aa052 in acpi_ns_evaluate(struct acpi_evaluate_info*) ../../third_party/acpica/source/components/namespace/nseval.c:250 +0x22a052 #9 0x000021e421413dd8 in acpi_ns_init_one_device(acpi_handle, u32, void*, void**) ../../third_party/acpica

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5a2d0dcb47b16f84880a59571eab8a004e3236d75a2d0dcb47b16f84880a59571eab8a004e3236d7
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35465c7a91c6b46e7c14d0c01d0084349a38ce5135465c7a91c6b46e7c14d0c01d0084349a38ce51
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 710e09fd116e2fa53e319a416ad4e4f8027682b6710e09fd116e2fa53e319a416ad4e4f8027682b6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 16359bc02c093b0862e31739c07673340a2106a616359bc02c093b0862e31739c07673340a2106a6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3a7a4aa3958ce0c4938a443d65001debe9a9af9c3a7a4aa3958ce0c4938a443d65001debe9a9af9c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8c4a7163b7f1495e3cc58bec7a4100de6612cde98c4a7163b7f1495e3cc58bec7a4100de6612cde9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3048c6b84a51e4ba4a89385ed218d19a670edd473048c6b84a51e4ba4a89385ed218d19a670edd47
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 05bb0167c80b8f93c6a4e0451b7da9b96db990c205bb0167c80b8f93c6a4e0451b7da9b96db990c2
linuxlinux_kernel< 4.14.3164.14.316
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 4.15 < 4.19.2844.19.284
linuxlinux_kernel>= 4.20 < 5.4.2445.4.244
linuxlinux_kernel>= 5.11 < 5.15.1135.15.113
linuxlinux_kernel>= 5.16 < 6.1.306.1.30
linuxlinux_kernel>= 5.5 < 5.10.1815.10.181
linuxlinux_kernel>= 6.2 < 6.3.46.3.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.