CVE-2023-54138
published 2025-12-24CVE-2023-54138: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on irq uninstall In case of early initialisation errors and on…
PriorityP420
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525104/
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f026e431cf861197dc03217d1920b38b80b31dd9 < e2d1cc82ad509c07a9ab0ab4bf88b6613fbf784b | e2d1cc82ad509c07a9ab0ab4bf88b6613fbf784b |
| linux | linux | >= f026e431cf861197dc03217d1920b38b80b31dd9 < dd8ce825b165acf997689c5ffa45d6a7a1fc0260 | dd8ce825b165acf997689c5ffa45d6a7a1fc0260 |
| linux | linux | >= f026e431cf861197dc03217d1920b38b80b31dd9 < bafa985acff9b0ed53957beff33c18be08d6b9a6 | bafa985acff9b0ed53957beff33c18be08d6b9a6 |
| linux | linux | >= f026e431cf861197dc03217d1920b38b80b31dd9 < 72092e34742e8b34accdadfa7bd9a13cf255a531 | 72092e34742e8b34accdadfa7bd9a13cf255a531 |
| linux | linux | >= f026e431cf861197dc03217d1920b38b80b31dd9 < cd459c005de3e2b855a8cc7768e633ce9d018e9f | cd459c005de3e2b855a8cc7768e633ce9d018e9f |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 5.15.0 < 5.15.112 | 5.15.112 |
| linux | linux_kernel | >= 5.16.0 < 6.1.29 | 6.1.29 |
| linux | linux_kernel | >= 6.2.0 < 6.2.16 | 6.2.16 |
| linux | linux_kernel | >= 6.3.0 < 6.3.3 | 6.3.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84w3-9hf3-rf66: In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors
ghsa_unreviewed·2025-12-24
CVE-2023-54138 GHSA-84w3-9hf3-rf66: In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525104/
OSV
CVE-2023-54138: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on irq uninstall In case of early initialisation errors an
osv·2025-12-24
CVE-2023-54138 CVE-2023-54138: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on irq uninstall In case of early initialisation errors an
In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on irq uninstall In case of early initialisation errors and on platforms that do not use the DPU controller, the deinitilisation code can be called with the kms pointer set to NULL. Patchwork: https://patchwork.freedesktop.org/patch/525104/
OSV
drm/msm: fix NULL-deref on irq uninstall
osv·2025-12-24
CVE-2023-54138 drm/msm: fix NULL-deref on irq uninstall
drm/msm: fix NULL-deref on irq uninstall
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525104/
Red Hat
kernel: drm/msm: fix NULL-deref on irq uninstall
vendor_redhat·2025-12-24
CVE-2023-54138 kernel: drm/msm: fix NULL-deref on irq uninstall
kernel: drm/msm: fix NULL-deref on irq uninstall
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525104/
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9
Debian
CVE-2023-54138: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm: fi...
vendor_debian·2023
CVE-2023-54138 CVE-2023-54138: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm: fi...
In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix NULL-deref on irq uninstall In case of early initialisation errors and on platforms that do not use the DPU controller, the deinitilisation code can be called with the kms pointer set to NULL. Patchwork: https://patchwork.freedesktop.org/patch/525104/
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54138 kernel: drm/msm: fix NULL-deref on irq uninstall
bugzilla·2025-12-24
CVE-2023-54138 CVE-2023-54138 kernel: drm/msm: fix NULL-deref on irq uninstall
CVE-2023-54138 kernel: drm/msm: fix NULL-deref on irq uninstall
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525104/
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122422-CVE-2023-54138-188c@gregkh/T
Wiz
CVE-2023-54138 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54138 CVE-2023-54138 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54138 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm/msm: fix NULL-deref on irq uninstall
In case of early initialisation errors and on platforms that do not use
the DPU controller, the deinitilisation code can be called with the kms
pointer set to NULL.
Patchwork: https://patchwork.freedesktop.org/patch/525104/
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-intel-iotg
kernel-devel-rt
Sources
NVD
Debian 12, 13, 1
https://git.kernel.org/stable/c/72092e34742e8b34accdadfa7bd9a13cf255a531https://git.kernel.org/stable/c/bafa985acff9b0ed53957beff33c18be08d6b9a6https://git.kernel.org/stable/c/cd459c005de3e2b855a8cc7768e633ce9d018e9fhttps://git.kernel.org/stable/c/dd8ce825b165acf997689c5ffa45d6a7a1fc0260https://git.kernel.org/stable/c/e2d1cc82ad509c07a9ab0ab4bf88b6613fbf784b
2025-12-24
Published