CVE-2023-54084 — Expired Pointer Dereference in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed to return an error code if init_stream()
failed, but it instead freed dg00x->rx_stream and returned success.
This potentially leads to a use after free.
Affected Packages4 packages
▶CVEListV5linux/linux9a08067ec318cbeaf0caa2d104cf677e723e02a3 — 5009aead17f060753428e249eb0246eb1c2f8b86+6
🔴Vulnerability Details
3GHSA▶
GHSA-h3h4-ggmf-jjqx: In the Linux kernel, the following vulnerability has been resolved:
ALSA: firewire-digi00x: prevent potential use after free
This code was supposed↗2025-12-24
OSV▶
CVE-2023-54084: In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to↗2025-12-24