CVE-2023-54186Use of Out-of-range Pointer Offset in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negative indexing of buf array in pin_assignment_show when get_current_pin_assignments returns 0 i.e. no compatible pin assignments are found. BUG: KASAN: use-after-free in pin_assignment_show+0x26c/0x33c ... Call trace: dump_backtrace+0x110/0x204 dump_stack_lvl+0x84/0xbc print_report+0x358/0x974 kasan_report+0x9c/0xfc __do_kernel_fault+0xd4/0x2d4 do_b

Affected Packages4 packages

Linuxlinux/linux_kernel4.19.04.19.284+5
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linux0e3bb7d6894d9b6e67d6382bb03a46a1dc9895880e61a7432fcd4bca06f05b7f1c7d7cb461880fe2+7
debiandebian/linux< linux 6.1.37-1 (bookworm)

🔴Vulnerability Details

3
OSV
usb: typec: altmodes/displayport: fix pin_assignment_show2025-12-30
OSV
CVE-2023-54186: In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negativ2025-12-30
GHSA
GHSA-xgf9-7jgm-fgxp: In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negat2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: usb: typec: altmodes/displayport: fix pin_assignment_show2025-12-30
Debian
CVE-2023-54186: linux - In the Linux kernel, the following vulnerability has been resolved: usb: typec:...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54186 Impact, Exploitability, and Mitigation Steps | Wiz