cbcvebase.
CVE-2023-53336
published 2025-09-17

CVE-2023-53336: In the Linux kernel, the following vulnerability has been resolved: media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings When…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: media: ipu-bridge: Fix null pointer deref on SSDB/PLD parsing warnings When ipu_bridge_parse_rotation() and ipu_bridge_parse_orientation() run sensor->adev is not set yet. So if either of the dev_warn() calls about unknown values are hit this will lead to a NULL pointer deref. Set sensor->adev earlier, with a borrowed ref to avoid making unrolling on errors harder, to fix this.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.5.3-1 (forky)linux 6.5.3-1 (forky)
linuxlinux
linuxlinux>= 485aa3df0dffa62d347ea4e0116f549338accc59 < 3de35e29cfddfe6bff762b15bcfe8d80bebac6cb3de35e29cfddfe6bff762b15bcfe8d80bebac6cb
linuxlinux>= 485aa3df0dffa62d347ea4e0116f549338accc59 < e08b091e33ecf6e4cb2c0c5820a69abe7673280be08b091e33ecf6e4cb2c0c5820a69abe7673280b
linuxlinux>= 485aa3df0dffa62d347ea4e0116f549338accc59 < 284be5693163343e1cf17c03917eecd1d6681bcf284be5693163343e1cf17c03917eecd1d6681bcf
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 5.16 < 6.4.166.4.16
linuxlinux_kernel>= 6.5 < 6.5.36.5.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.