CVE-2023-54084Expired Pointer Dereference in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to return an error code if init_stream() failed, but it instead freed dg00x->rx_stream and returned success. This potentially leads to a use after free.

Affected Packages4 packages

Linuxlinux/linux_kernel5.4.05.4.244+4
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linux9a08067ec318cbeaf0caa2d104cf677e723e02a35009aead17f060753428e249eb0246eb1c2f8b86+6
debiandebian/linux< linux 6.1.37-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-h3h4-ggmf-jjqx: In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed2025-12-24
OSV
ALSA: firewire-digi00x: prevent potential use after free2025-12-24
OSV
CVE-2023-54084: In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-digi00x: prevent potential use after free This code was supposed to2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: ALSA: firewire-digi00x: prevent potential use after free2025-12-24
Debian
CVE-2023-54084: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: firew...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54084 Impact, Exploitability, and Mitigation Steps | Wiz