cbcvebase.
CVE-2023-54056
published 2025-12-24

CVE-2023-54056: In the Linux kernel, the following vulnerability has been resolved: kheaders: Use array declaration instead of char Under CONFIG_FORTIFY_SOURCE, memcpy() will…

PriorityP423low5.5
EPSS
0.20%
9.8th percentile
In the Linux kernel, the following vulnerability has been resolved: kheaders: Use array declaration instead of char Under CONFIG_FORTIFY_SOURCE, memcpy() will check the size of destination and source buffers. Defining kernel_headers_data as "char" would trip this check. Since these addresses are treated as byte arrays, define them as arrays (as done everywhere else). This was seen with: $ cat /sys/kernel/kheaders.tar.xz >> /dev/null detected buffer overflow in memcpy kernel BUG at lib/string_helpers.c:1027! ... RIP: 0010:fortify_panic+0xf/0x20 [...] Call Trace: ikheaders_read+0x45/0x50 [kheaders] kernfs_fop_read_iter+0x1a4/0x2f0 ...

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 43d8ce9d65a54846d378545770991e65838981e0 < 719459877d58c8aced5845c1e5b98d8d87d09197719459877d58c8aced5845c1e5b98d8d87d09197
linuxlinux>= 43d8ce9d65a54846d378545770991e65838981e0 < fcd2da2e6bf2640a31a2a5b118b50dc3635c707bfcd2da2e6bf2640a31a2a5b118b50dc3635c707b
linuxlinux>= 43d8ce9d65a54846d378545770991e65838981e0 < 4a07d2d511e2703efd4387891d49e0326f1157f34a07d2d511e2703efd4387891d49e0326f1157f3
linuxlinux>= 43d8ce9d65a54846d378545770991e65838981e0 < b9f6845a492de20679b84bda6b08be347c5819dab9f6845a492de20679b84bda6b08be347c5819da
linuxlinux>= 43d8ce9d65a54846d378545770991e65838981e0 < d6d1af6b8611801b585c53c0cc63626c8d339e96d6d1af6b8611801b585c53c0cc63626c8d339e96
linuxlinux>= 43d8ce9d65a54846d378545770991e65838981e0 < 82d2e01b95c439fe55fab5e04fc83387c42d3a4882d2e01b95c439fe55fab5e04fc83387c42d3a48
linuxlinux>= 43d8ce9d65a54846d378545770991e65838981e0 < b69edab47f1da8edd8e7bfdf8c70f51a2a5d89fbb69edab47f1da8edd8e7bfdf8c70f51a2a5d89fb
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 5.11.0 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16.0 < 6.1.286.1.28
linuxlinux_kernel>= 5.2.0 < 5.4.2435.4.243
linuxlinux_kernel>= 5.5.0 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2.0 < 6.2.156.2.15
linuxlinux_kernel>= 6.3.0 < 6.3.26.3.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.