cbcvebase.
CVE-2023-54066
published 2025-12-24

CVE-2023-54066: In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: gl861: Fix null-ptr-deref in gl861_i2c_master_xfer In…

PriorityP420low5.5
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: gl861: Fix null-ptr-deref in gl861_i2c_master_xfer In gl861_i2c_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach gl861_i2c_master_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()")

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.55-1 (bookworm)linux 6.1.55-1 (bookworm)
linuxlinux
linuxlinux>= 1ea76d16569b7fc242b860c7e19549be028b13d1 < 578b67614ae0e4fba3945b66a4c8f9ae77115bcb578b67614ae0e4fba3945b66a4c8f9ae77115bcb
linuxlinux>= 1ea76d16569b7fc242b860c7e19549be028b13d1 < 2a33fc57133d6f39d62285df6706aeb1714967f12a33fc57133d6f39d62285df6706aeb1714967f1
linuxlinux>= 1ea76d16569b7fc242b860c7e19549be028b13d1 < dfcd3c010209927b9f45b860f046635dc32e32e1dfcd3c010209927b9f45b860f046635dc32e32e1
linuxlinux>= 1ea76d16569b7fc242b860c7e19549be028b13d1 < 72af676551efe820e309a6c7681c2c4372f3737672af676551efe820e309a6c7681c2c4372f37376
linuxlinux>= 1ea76d16569b7fc242b860c7e19549be028b13d1 < b97719a66970601cd3151a3e2020f4454a1c4ff6b97719a66970601cd3151a3e2020f4454a1c4ff6
linuxlinux_kernel>= 0 < 5.10.197-15.10.197-1
linuxlinux_kernel>= 0 < 6.1.55-16.1.55-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 0 < 6.5.6-16.5.6-1
linuxlinux_kernel>= 5.11.0 < 5.15.1335.15.133
linuxlinux_kernel>= 5.16.0 < 6.1.556.1.55
linuxlinux_kernel>= 5.5.0 < 5.10.1975.10.197
linuxlinux_kernel>= 6.2.0 < 6.5.56.5.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.