CVE-2023-53392NULL Pointer Dereference in Linux

Severity
7.1HIGHNVD
EPSS
0.0%
top 97.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix kernel panic during warm reset During warm reset device->fw_client is set to NULL. If a bus driver is registered after this NULL setting and before new firmware clients are enumerated by ISHTP, kernel panic will result in the function ishtp_cl_bus_match(). This is because of reference to device->fw_client->props.protocol_name. ISH firmware after getting successfully loaded, sends a warm reset notificat

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

NVDlinux/linux_kernel5.16.16.1.25+3
Debianlinux/linux_kernel< 6.1.25-1+2
CVEListV5linux/linux44e2a58cb8803e3e40eaf5708c4d15b4118913c46c8cc40c588f8080a164d88336b1490279e0f1da+3
debiandebian/linux< linux 6.1.25-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2023-53392: In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix kernel panic during warm reset During warm reset device->f2025-09-18
GHSA
GHSA-h5fg-gggq-x5vh: In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix kernel panic during warm reset During warm reset device-2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: HID: intel-ish-hid: Fix kernel panic during warm reset2025-09-18
Debian
CVE-2023-53392: linux - In the Linux kernel, the following vulnerability has been resolved: HID: intel-...2023
CVE-2023-53392 — NULL Pointer Dereference in Linux | cvebase