CVE-2023-54049
published 2025-12-24CVE-2023-54049: In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: Add check for kstrdup Add check for the return value of kstrdup() and return…
PriorityP419
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.55-1 (bookworm) | linux 6.1.55-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < 5197498c902502127a47abda5359dd7f1d41946f | 5197498c902502127a47abda5359dd7f1d41946f |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < 13928a837e0f014dac0322dd9f8a67c486e7f232 | 13928a837e0f014dac0322dd9f8a67c486e7f232 |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < efa7f31669f04084ed5996ed467ba529f4c90467 | efa7f31669f04084ed5996ed467ba529f4c90467 |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < 71ac2ffd7f80fdd350486f6645dc48456e55a59b | 71ac2ffd7f80fdd350486f6645dc48456e55a59b |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < abd740db896b3c588dced175af98b95852c1854b | abd740db896b3c588dced175af98b95852c1854b |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < cae0787e408c30a575760a531ccb69a6b48bbfaf | cae0787e408c30a575760a531ccb69a6b48bbfaf |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < 174cf8853857c190a3c4f1f1d2d06cfd095fe859 | 174cf8853857c190a3c4f1f1d2d06cfd095fe859 |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < e3734a9558afac91df3c655a6f2376b9d14933b7 | e3734a9558afac91df3c655a6f2376b9d14933b7 |
| linux | linux | >= b4f8e52b89f69f5563ac4cb9ffdacc4418917af1 < b5c9ee8296a3760760c7b5d2e305f91412adc795 | b5c9ee8296a3760760c7b5d2e305f91412adc795 |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.55-1 | 6.1.55-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 0 < 6.5.3-1 | 6.5.3-1 |
| linux | linux_kernel | >= 4.13.0 < 4.14.326 | 4.14.326 |
| linux | linux_kernel | >= 4.15.0 < 4.19.295 | 4.19.295 |
| linux | linux_kernel | >= 4.20.0 < 5.4.257 | 5.4.257 |
| linux | linux_kernel | >= 5.11.0 < 5.15.132 | 5.15.132 |
| linux | linux_kernel | >= 5.16.0 < 6.1.53 | 6.1.53 |
| linux | linux_kernel | >= 5.5.0 < 5.10.195 | 5.10.195 |
| linux | linux_kernel | >= 6.2.0 < 6.4.16 | 6.4.16 |
| linux | linux_kernel | >= 6.5.0 < 6.5.3 | 6.5.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: rpmsg: glink: Add check for kstrdup
vendor_redhat·2025-12-24
CVE-2023-54049 kernel: rpmsg: glink: Add check for kstrdup
kernel: rpmsg: glink: Add check for kstrdup
In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2023-54049: linux - In the Linux kernel, the following vulnerability has been resolved: rpmsg: glin...
vendor_debian·2023
CVE-2023-54049 CVE-2023-54049: linux - In the Linux kernel, the following vulnerability has been resolved: rpmsg: glin...
In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 6.1.55-1)
bullseye: resolved (fixed in 5.10.197-1)
forky: resolved (fixed in 6.5.3-1)
sid: resolved (fixed in 6.5.3-1)
trixie: resolved (fixed in 6.5.3-1)
GHSA
GHSA-r9ff-8j26-q598: In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup()
ghsa_unreviewed·2025-12-24
CVE-2023-54049 GHSA-r9ff-8j26-q598: In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup()
In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
OSV
CVE-2023-54049: In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: Add check for kstrdup Add check for the return value of kstrdup() an
osv·2025-12-24
CVE-2023-54049 CVE-2023-54049: In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: Add check for kstrdup Add check for the return value of kstrdup() an
In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference.
OSV
rpmsg: glink: Add check for kstrdup
osv·2025-12-24
CVE-2023-54049 rpmsg: glink: Add check for kstrdup
rpmsg: glink: Add check for kstrdup
In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54049 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54049 CVE-2023-54049 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54049 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
dtb-freescale
dtb-mediatek
Sources
NVD
Debian 11, 12, 13, 14 Has Fix Added at: Dec 26, 2025
Echo Has Fix Added at: Dec 26, 2025
Ubuntu 16.04 Severity MEDIUM No Fix Add
Bugzilla
CVE-2023-54049 kernel: rpmsg: glink: Add check for kstrdup
bugzilla·2025-12-24
CVE-2023-54049 CVE-2023-54049 kernel: rpmsg: glink: Add check for kstrdup
CVE-2023-54049 kernel: rpmsg: glink: Add check for kstrdup
In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: Add check for kstrdup
Add check for the return value of kstrdup() and return the error
if it fails in order to avoid NULL pointer dereference.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122424-CVE-2023-54049-79f7@gregkh/T
https://git.kernel.org/stable/c/13928a837e0f014dac0322dd9f8a67c486e7f232https://git.kernel.org/stable/c/174cf8853857c190a3c4f1f1d2d06cfd095fe859https://git.kernel.org/stable/c/5197498c902502127a47abda5359dd7f1d41946fhttps://git.kernel.org/stable/c/71ac2ffd7f80fdd350486f6645dc48456e55a59bhttps://git.kernel.org/stable/c/abd740db896b3c588dced175af98b95852c1854bhttps://git.kernel.org/stable/c/b5c9ee8296a3760760c7b5d2e305f91412adc795https://git.kernel.org/stable/c/cae0787e408c30a575760a531ccb69a6b48bbfafhttps://git.kernel.org/stable/c/e3734a9558afac91df3c655a6f2376b9d14933b7https://git.kernel.org/stable/c/efa7f31669f04084ed5996ed467ba529f4c90467
2025-12-24
Published