CVE-2023-54093NULL Pointer Dereference in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: media: anysee: fix null-ptr-deref in anysee_master_xfer In anysee_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach anysee_master_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az60

Affected Packages4 packages

Linuxlinux/linux_kernel2.6.274.14.326+6
Debianlinux/linux_kernel< 5.10.197-1+3
CVEListV5linux/linuxa51e34dd6080d8d5c9e95a4e0292cd4cb889a61b73c0b224ceeba12dee2a7a8cbc147648da0b2e63+8
debiandebian/linux< linux 6.1.55-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-4q89-7p83-q89w: In the Linux kernel, the following vulnerability has been resolved: media: anysee: fix null-ptr-deref in anysee_master_xfer In anysee_master_xfer, m2025-12-24
OSV
media: anysee: fix null-ptr-deref in anysee_master_xfer2025-12-24
OSV
CVE-2023-54093: In the Linux kernel, the following vulnerability has been resolved: media: anysee: fix null-ptr-deref in anysee_master_xfer In anysee_master_xfer, msg2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service in anysee media driver via null pointer dereference2025-12-24
Debian
CVE-2023-54093: linux - In the Linux kernel, the following vulnerability has been resolved: media: anys...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54093 Impact, Exploitability, and Mitigation Steps | Wiz