cbcvebase.
CVE-2023-53648
published 2025-10-07

CVE-2023-53648: In the Linux kernel, the following vulnerability has been resolved: ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer smatch error…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer smatch error: sound/pci/ac97/ac97_codec.c:2354 snd_ac97_mixer() error: we previously assumed 'rac97' could be null (see line 2072) remove redundant assignment, return error if rac97 is NULL.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.52-1 (bookworm)linux 6.1.52-1 (bookworm)
linuxlinux
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < 809af7bb4219bdeef0dbb8b2ed700d6516d13fe9809af7bb4219bdeef0dbb8b2ed700d6516d13fe9
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < e4cccff1e7ab6ea30995b6fbbb007d02647e025ce4cccff1e7ab6ea30995b6fbbb007d02647e025c
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < 5f13d67027fa782096e6aee0db5dce61c4aeb6135f13d67027fa782096e6aee0db5dce61c4aeb613
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < f923a582217b198b557756809ffe42ac0fad6adbf923a582217b198b557756809ffe42ac0fad6adb
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < 300e26e3e64880de5013eac8831cf44387ef752c300e26e3e64880de5013eac8831cf44387ef752c
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < d28b83252e150155b8b8c65b612c555e93c8b45fd28b83252e150155b8b8c65b612c555e93c8b45f
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < 09baf460dfba79ee6a0c72e68ccdbbba84d894df09baf460dfba79ee6a0c72e68ccdbbba84d894df
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < 228da1fa124470606ac19783e551f9d51a1e01b0228da1fa124470606ac19783e551f9d51a1e01b0
linuxlinux>= da3cec35dd3c31d8706db4bf379372ce70d92118 < 79597c8bf64ca99eab385115743131d260339da579597c8bf64ca99eab385115743131d260339da5
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.52-16.1.52-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 0 < 6.4.4-16.4.4-1
linuxlinux_kernel>= 2.6.28 < 4.14.3224.14.322
linuxlinux_kernel>= 4.15 < 4.19.2914.19.291
linuxlinux_kernel>= 4.20 < 5.4.2515.4.251
linuxlinux_kernel>= 5.11 < 5.15.1215.15.121
linuxlinux_kernel>= 5.16 < 6.1.396.1.39
linuxlinux_kernel>= 5.5 < 5.10.1885.10.188
linuxlinux_kernel>= 6.2 < 6.3.136.3.13
linuxlinux_kernel>= 6.4 < 6.4.46.4.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.