CVE-2023-54189NULL Pointer Dereference in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer dereference.

Affected Packages4 packages

Linuxlinux/linux_kernel5.5.05.10.188+5
Debianlinux/linux_kernel< 5.10.191-1+3
CVEListV5linux/linuxc617a3b777b92a0e80ceff2dffaae9350d4c38508430a8e8e85420d4cb51dcb08b0278ab194ea82f+7
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2023-54189: In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Add check for kstrdup Add check for the return value of kstrdup() and2025-12-30
OSV
pstore/ram: Add check for kstrdup2025-12-30
GHSA
GHSA-xhm8-cfh8-8hcp: In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Add check for kstrdup Add check for the return value of kstrdup() an2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Denial of Service via NULL pointer dereference in pstore/ram2025-12-30
Debian
CVE-2023-54189: linux - In the Linux kernel, the following vulnerability has been resolved: pstore/ram:...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54189 Impact, Exploitability, and Mitigation Steps | Wiz