CVE-2023-54084
published 2025-12-24CVE-2023-54084: In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return…
PriorityP423low5.5
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 9a08067ec318cbeaf0caa2d104cf677e723e02a3 < 5009aead17f060753428e249eb0246eb1c2f8b86 | 5009aead17f060753428e249eb0246eb1c2f8b86 |
| linux | linux | >= 9a08067ec318cbeaf0caa2d104cf677e723e02a3 < 13c5fa1248bf06e95a25907c1be83948b8c44c50 | 13c5fa1248bf06e95a25907c1be83948b8c44c50 |
| linux | linux | >= 9a08067ec318cbeaf0caa2d104cf677e723e02a3 < bbb5ac533ca6c4e2775a95388c9c0c610bb442b7 | bbb5ac533ca6c4e2775a95388c9c0c610bb442b7 |
| linux | linux | >= 9a08067ec318cbeaf0caa2d104cf677e723e02a3 < ee1a221d947809c0308f27567c07a3ac93406057 | ee1a221d947809c0308f27567c07a3ac93406057 |
| linux | linux | >= 9a08067ec318cbeaf0caa2d104cf677e723e02a3 < 67148395efa2c1fb20e98fca359b20e7a6c81fe4 | 67148395efa2c1fb20e98fca359b20e7a6c81fe4 |
| linux | linux | >= 9a08067ec318cbeaf0caa2d104cf677e723e02a3 < c0e72058d5e21982e61a29de6b098f7c1f0db498 | c0e72058d5e21982e61a29de6b098f7c1f0db498 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 5.11.0 < 5.15.113 | 5.15.113 |
| linux | linux_kernel | >= 5.16.0 < 6.1.30 | 6.1.30 |
| linux | linux_kernel | >= 5.4.0 < 5.4.244 | 5.4.244 |
| linux | linux_kernel | >= 5.5.0 < 5.10.181 | 5.10.181 |
| linux | linux_kernel | >= 6.2.0 < 6.3.4 | 6.3.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h3h4-ggmf-jjqx: In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed
ghsa_unreviewed·2025-12-24
CVE-2023-54084 GHSA-h3h4-ggmf-jjqx: In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
OSV
ALSA: firewire-digi00x: prevent potential use after free
osv·2025-12-24
CVE-2023-54084 ALSA: firewire-digi00x: prevent potential use after free
ALSA: firewire-digi00x: prevent potential use after free
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
OSV
CVE-2023-54084: In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to
osv·2025-12-24
CVE-2023-54084 CVE-2023-54084: In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to
In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return an error code if init_stream() failed, but it instead freed dg00x->rx_stream and returned success. This potentially leads to a use after free.
Red Hat
kernel: ALSA: firewire-digi00x: prevent potential use after free
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54084 [LOW] CWE-825 kernel: ALSA: firewire-digi00x: prevent potential use after free
kernel: ALSA: firewire-digi00x: prevent potential use after free
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
A potential use-after-free vulnerability was found in the Linux kernel's ALSA firewire-digi00x driver. When init_stream() fails, the error handling code incorrectly frees dg00x->rx_stream but returns success instead of an error code. This leaves a dangling pointer that can be dereferenced later, leading to a use-after-free condition.
Statement: This flaw affects systems with Digidesign Digi 002/003 FireWire audio interfaces usi
Debian
CVE-2023-54084: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: firew...
vendor_debian·2023
CVE-2023-54084 CVE-2023-54084: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: firew...
In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return an error code if init_stream() failed, but it instead freed dg00x->rx_stream and returned success. This potentially leads to a use after free.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54084 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54084 CVE-2023-54084 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54084 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-oracle
kernel
Sources
NVD
Debian 11, 12, 13, 14 Has Fix Added at: Dec 26, 2025
Echo Ha
Bugzilla
CVE-2023-54084 kernel: ALSA: firewire-digi00x: prevent potential use after free
bugzilla·2025-12-24
CVE-2023-54084 [LOW] CVE-2023-54084 kernel: ALSA: firewire-digi00x: prevent potential use after free
CVE-2023-54084 kernel: ALSA: firewire-digi00x: prevent potential use after free
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122404-CVE-2023-54084-a862@gregkh/T
https://git.kernel.org/stable/c/13c5fa1248bf06e95a25907c1be83948b8c44c50https://git.kernel.org/stable/c/5009aead17f060753428e249eb0246eb1c2f8b86https://git.kernel.org/stable/c/67148395efa2c1fb20e98fca359b20e7a6c81fe4https://git.kernel.org/stable/c/bbb5ac533ca6c4e2775a95388c9c0c610bb442b7https://git.kernel.org/stable/c/c0e72058d5e21982e61a29de6b098f7c1f0db498https://git.kernel.org/stable/c/ee1a221d947809c0308f27567c07a3ac93406057
2025-12-24
Published