CVE-2023-53837
published 2025-12-09CVE-2023-53837: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on snapshot tear down In case of early initialisation errors and on…
PriorityP421
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525099/
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 98659487b845c05b6bed85d881713545db674c7c < 8f0e1ad5327a3499e7f09157cb714302a856e8a4 | 8f0e1ad5327a3499e7f09157cb714302a856e8a4 |
| linux | linux | >= 98659487b845c05b6bed85d881713545db674c7c < 16e0e6fb4511c004a5a0987d5bd75d9bcfb2b175 | 16e0e6fb4511c004a5a0987d5bd75d9bcfb2b175 |
| linux | linux | >= 98659487b845c05b6bed85d881713545db674c7c < 8eca32b5b92a0be956a8934d7eddf4f70c107927 | 8eca32b5b92a0be956a8934d7eddf4f70c107927 |
| linux | linux | >= 98659487b845c05b6bed85d881713545db674c7c < 19fe79ae816a7e3400df1eb4d27530bf9b8ae258 | 19fe79ae816a7e3400df1eb4d27530bf9b8ae258 |
| linux | linux | >= 98659487b845c05b6bed85d881713545db674c7c < a465353b9250802f87b97123e33a17f51277f0b1 | a465353b9250802f87b97123e33a17f51277f0b1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 5.14.0 < 5.15.112 | 5.15.112 |
| linux | linux_kernel | >= 5.16.0 < 6.1.29 | 6.1.29 |
| linux | linux_kernel | >= 6.2.0 < 6.2.16 | 6.2.16 |
| linux | linux_kernel | >= 6.3.0 < 6.3.3 | 6.3.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-53837: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on snapshot tear down In case of early initialisation erro
osv·2025-12-09
CVE-2023-53837 CVE-2023-53837: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on snapshot tear down In case of early initialisation erro
In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on snapshot tear down In case of early initialisation errors and on platforms that do not use the DPU controller, the deinitilisation code can be called with the kms pointer set to NULL. Patchwork: https://patchwork.freedesktop.org/patch/525099/
OSV
drm/msm: fix NULL-deref on snapshot tear down
osv·2025-12-09
CVE-2023-53837 drm/msm: fix NULL-deref on snapshot tear down
drm/msm: fix NULL-deref on snapshot tear down
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525099/
GHSA
GHSA-4m3g-fqr7-qqgh: In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation er
ghsa_unreviewed·2025-12-09
CVE-2023-53837 GHSA-4m3g-fqr7-qqgh: In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation er
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525099/
Red Hat
kernel: drm/msm: fix NULL-deref on snapshot tear down
vendor_redhat·2025-12-09
CVE-2023-53837 kernel: drm/msm: fix NULL-deref on snapshot tear down
kernel: drm/msm: fix NULL-deref on snapshot tear down
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525099/
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterpri
Debian
CVE-2023-53837: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm: fi...
vendor_debian·2023
CVE-2023-53837 CVE-2023-53837: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm: fi...
In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on snapshot tear down In case of early initialisation errors and on platforms that do not use the DPU controller, the deinitilisation code can be called with the kms pointer set to NULL. Patchwork: https://patchwork.freedesktop.org/patch/525099/
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-53837 kernel: drm/msm: fix NULL-deref on snapshot tear down
bugzilla·2025-12-09
CVE-2023-53837 CVE-2023-53837 kernel: drm/msm: fix NULL-deref on snapshot tear down
CVE-2023-53837 kernel: drm/msm: fix NULL-deref on snapshot tear down
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525099/
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025120956-CVE-2023-53837-2bf8@gregkh/T
Wiz
CVE-2023-53837 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-53837 CVE-2023-53837 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-53837 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on snapshot tear down
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525099/
Source : NVD
Published December 9, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-default-base
linux-azure-5.15
Sources
NVD
Debian 1
https://git.kernel.org/stable/c/16e0e6fb4511c004a5a0987d5bd75d9bcfb2b175https://git.kernel.org/stable/c/19fe79ae816a7e3400df1eb4d27530bf9b8ae258https://git.kernel.org/stable/c/8eca32b5b92a0be956a8934d7eddf4f70c107927https://git.kernel.org/stable/c/8f0e1ad5327a3499e7f09157cb714302a856e8a4https://git.kernel.org/stable/c/a465353b9250802f87b97123e33a17f51277f0b1
2025-12-09
Published