CVE-2023-54186 — Use of Out-of-range Pointer Offset in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Description
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: altmodes/displayport: fix pin_assignment_show
This patch fixes negative indexing of buf array in pin_assignment_show
when get_current_pin_assignments returns 0 i.e. no compatible pin
assignments are found.
BUG: KASAN: use-after-free in pin_assignment_show+0x26c/0x33c
...
Call trace:
dump_backtrace+0x110/0x204
dump_stack_lvl+0x84/0xbc
print_report+0x358/0x974
kasan_report+0x9c/0xfc
__do_kernel_fault+0xd4/0x2d4
do_b…
Affected Packages4 packages
▶CVEListV5linux/linux0e3bb7d6894d9b6e67d6382bb03a46a1dc989588 — 0e61a7432fcd4bca06f05b7f1c7d7cb461880fe2+7
🔴Vulnerability Details
3OSV▶
CVE-2023-54186: In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negativ↗2025-12-30
GHSA▶
GHSA-xgf9-7jgm-fgxp: In the Linux kernel, the following vulnerability has been resolved:
usb: typec: altmodes/displayport: fix pin_assignment_show
This patch fixes negat↗2025-12-30