cbcvebase.
CVE-2023-53784
published 2025-12-09

CVE-2023-53784: In the Linux kernel, the following vulnerability has been resolved: drm: bridge: dw_hdmi: fix connector access for scdc Commit 5d844091f237 ("drm/scdc-helper…

PriorityP421low4.7
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: drm: bridge: dw_hdmi: fix connector access for scdc Commit 5d844091f237 ("drm/scdc-helper: Pimp SCDC debugs") changed the scdc interface to pick up an i2c adapter from a connector instead. However, in the case of dw-hdmi, the wrong connector was being used to pass i2c adapter information, since dw-hdmi's embedded connector structure is only populated when the bridge attachment callback explicitly asks for it. drm-meson is handling connector creation, so this won't happen, leading to a NULL pointer dereference. Fix it by having scdc functions access dw-hdmi's current connector pointer instead, which is assigned during the bridge enablement stage. [narmstrong: moved Fixes tag before first S-o-b and added Reported-by tag]

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.4.11-1 (forky)linux 6.4.11-1 (forky)
linuxlinux
linuxlinux>= 5d844091f2370f01752c3129b147861b9dcd3d98 < 552f79aa9e801ed4f74d6b3221af78042ba4f235552f79aa9e801ed4f74d6b3221af78042ba4f235
linuxlinux>= 5d844091f2370f01752c3129b147861b9dcd3d98 < 98703e4e061fb8715c7613cd227e32cdfd136b2398703e4e061fb8715c7613cd227e32cdfd136b23
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 0 < 6.4.11-16.4.11-1
linuxlinux_kernel>= 6.4.0 < 6.4.56.4.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.