CVE-2023-54150
published 2025-12-24CVE-2023-54150: In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix an out of bounds error in BIOS parser The array is hardcoded to 8 in…
PriorityP420medium5.5
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 in atomfirmware.h, but firmware provides
a bigger one sometimes. Deferencing the larger array causes an out
of bounds error.
commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error
in bios parser") fixed some of this, but there are two other cases
not covered by it. Fix those as well.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < b8e7589f50b709b647b642531599e70707faf70c | b8e7589f50b709b647b642531599e70707faf70c |
| linux | linux | >= ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 66acfe798cd08b36cfbb65a30fab3159811304a7 | 66acfe798cd08b36cfbb65a30fab3159811304a7 |
| linux | linux | >= ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < 5675ecd2e0b00a4318ba1db1a1234e7d45b13d6b | 5675ecd2e0b00a4318ba1db1a1234e7d45b13d6b |
| linux | linux | >= ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < dea2dbec716c38a0b73b6ad01d91e2b120cc5f1e | dea2dbec716c38a0b73b6ad01d91e2b120cc5f1e |
| linux | linux | >= ae79c310b1a6f97429a5784b65f125d9cc9c95b1 < d116db180decec1b21bba31d2ff495ac4d8e1b83 | d116db180decec1b21bba31d2ff495ac4d8e1b83 |
| linux | linux_kernel | >= 0 < 5.10.191-1 | 5.10.191-1 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 4.15.0 < 5.10.181 | 5.10.181 |
| linux | linux_kernel | >= 5.11.0 < 5.15.113 | 5.15.113 |
| linux | linux_kernel | >= 5.16.0 < 6.1.30 | 6.1.30 |
| linux | linux_kernel | >= 6.2.0 < 6.3.4 | 6.3.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g4x6-vrjg-m8w6: In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 i
ghsa_unreviewed·2025-12-24
CVE-2023-54150 GHSA-g4x6-vrjg-m8w6: In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 i
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 in atomfirmware.h, but firmware provides
a bigger one sometimes. Deferencing the larger array causes an out
of bounds error.
commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error
in bios parser") fixed some of this, but there are two other cases
not covered by it. Fix those as well.
OSV
CVE-2023-54150: In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix an out of bounds error in BIOS parser The array is hardcoded to 8 in
osv·2025-12-24
CVE-2023-54150 CVE-2023-54150: In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix an out of bounds error in BIOS parser The array is hardcoded to 8 in
In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix an out of bounds error in BIOS parser The array is hardcoded to 8 in atomfirmware.h, but firmware provides a bigger one sometimes. Deferencing the larger array causes an out of bounds error. commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error in bios parser") fixed some of this, but there are two other cases not covered by it. Fix those as well.
OSV
drm/amd: Fix an out of bounds error in BIOS parser
osv·2025-12-24
CVE-2023-54150 drm/amd: Fix an out of bounds error in BIOS parser
drm/amd: Fix an out of bounds error in BIOS parser
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 in atomfirmware.h, but firmware provides
a bigger one sometimes. Deferencing the larger array causes an out
of bounds error.
commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error
in bios parser") fixed some of this, but there are two other cases
not covered by it. Fix those as well.
Red Hat
kernel: drm/amd: Fix an out of bounds error in BIOS parser
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2023-54150 [MEDIUM] CWE-1285 kernel: drm/amd: Fix an out of bounds error in BIOS parser
kernel: drm/amd: Fix an out of bounds error in BIOS parser
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 in atomfirmware.h, but firmware provides
a bigger one sometimes. Deferencing the larger array causes an out
of bounds error.
commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error
in bios parser") fixed some of this, but there are two other cases
not covered by it. Fix those as well.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linu
Debian
CVE-2023-54150: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fi...
vendor_debian·2023
CVE-2023-54150 CVE-2023-54150: linux - In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fi...
In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix an out of bounds error in BIOS parser The array is hardcoded to 8 in atomfirmware.h, but firmware provides a bigger one sometimes. Deferencing the larger array causes an out of bounds error. commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error in bios parser") fixed some of this, but there are two other cases not covered by it. Fix those as well.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved (fixed in 5.10.191-1)
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54150 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54150 CVE-2023-54150 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54150 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 in atomfirmware.h, but firmware provides
a bigger one sometimes. Deferencing the larger array causes an out
of bounds error.
commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error
in bios parser") fixed some of this, but there are two other cases
not covered by it. Fix those as well.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Prob
Bugzilla
CVE-2023-54150 kernel: drm/amd: Fix an out of bounds error in BIOS parser
bugzilla·2025-12-24
CVE-2023-54150 [MEDIUM] CVE-2023-54150 kernel: drm/amd: Fix an out of bounds error in BIOS parser
CVE-2023-54150 kernel: drm/amd: Fix an out of bounds error in BIOS parser
In the Linux kernel, the following vulnerability has been resolved:
drm/amd: Fix an out of bounds error in BIOS parser
The array is hardcoded to 8 in atomfirmware.h, but firmware provides
a bigger one sometimes. Deferencing the larger array causes an out
of bounds error.
commit 4fc1ba4aa589 ("drm/amd/display: fix array index out of bound error
in bios parser") fixed some of this, but there are two other cases
not covered by it. Fix those as well.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122426-CVE-2023-54150-dbc1@gregkh/T
https://git.kernel.org/stable/c/5675ecd2e0b00a4318ba1db1a1234e7d45b13d6bhttps://git.kernel.org/stable/c/66acfe798cd08b36cfbb65a30fab3159811304a7https://git.kernel.org/stable/c/b8e7589f50b709b647b642531599e70707faf70chttps://git.kernel.org/stable/c/d116db180decec1b21bba31d2ff495ac4d8e1b83https://git.kernel.org/stable/c/dea2dbec716c38a0b73b6ad01d91e2b120cc5f1e
2025-12-24
Published