CVE-2023-54233
published 2025-12-30CVE-2023-54233: In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains…
PriorityP418low3.3
EPSS
0.16%
5.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology contains an unsupported widget, its .module_info
field won't be set, then sof_ipc4_route_setup() will cause a kernel
Oops trying to dereference it. Add a check for such cases.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.3.7-1 (forky) | linux 6.3.7-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 3acd527089463742a3dd95e274d53c2fdd834716 < 170818974e9732506195c6302743856cc8bdfd6f | 170818974e9732506195c6302743856cc8bdfd6f |
| linux | linux | >= 3acd527089463742a3dd95e274d53c2fdd834716 < e3720f92e0237921da537e47a0b24e27899203f8 | e3720f92e0237921da537e47a0b24e27899203f8 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 6.0.0 < 6.2.11 | 6.2.11 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.2.10 ASoC sof_ipc4_route_setup null pointer dereference (WID-SEC-2025-2941)
vuldb·2026-04-27
CVE-2023-54233 [CRITICAL] Linux Kernel up to 6.2.10 ASoC sof_ipc4_route_setup null pointer dereference (WID-SEC-2025-2941)
A vulnerability described as critical has been identified in Linux Kernel up to 6.2.10. This issue affects the function sof_ipc4_route_setup of the component ASoC. Executing a manipulation can lead to null pointer dereference.
This vulnerability is registered as CVE-2023-54233. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
OSV
ASoC: SOF: avoid a NULL dereference with unsupported widgets
osv·2025-12-30
CVE-2023-54233 ASoC: SOF: avoid a NULL dereference with unsupported widgets
ASoC: SOF: avoid a NULL dereference with unsupported widgets
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology contains an unsupported widget, its .module_info
field won't be set, then sof_ipc4_route_setup() will cause a kernel
Oops trying to dereference it. Add a check for such cases.
GHSA
GHSA-h352-qwh6-g54m: In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology
ghsa_unreviewed·2025-12-30
CVE-2023-54233 GHSA-h352-qwh6-g54m: In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology contains an unsupported widget, its .module_info
field won't be set, then sof_ipc4_route_setup() will cause a kernel
Oops trying to dereference it. Add a check for such cases.
OSV
CVE-2023-54233: In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology c
osv·2025-12-30
CVE-2023-54233 CVE-2023-54233: In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology c
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.
Red Hat
kernel: ASoC: SOF: avoid a NULL dereference with unsupported widgets
vendor_redhat·2025-12-30·CVSS 3.3
CVE-2023-54233 [LOW] CWE-476 kernel: ASoC: SOF: avoid a NULL dereference with unsupported widgets
kernel: ASoC: SOF: avoid a NULL dereference with unsupported widgets
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology contains an unsupported widget, its .module_info
field won't be set, then sof_ipc4_route_setup() will cause a kernel
Oops trying to dereference it. Add a check for such cases.
A NULL pointer dereference was found in the Sound Open Firmware (SOF) driver. When a topology contains an unsupported widget type, the module_info field is NULL, and dereferencing it during route setup crashes the kernel.
Statement: This requires loading a malformed or incompatible audio topology file. Normal audio operation with supported hardware and topologies is unaffected. Custom topology develo
Debian
CVE-2023-54233: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ...
vendor_debian·2023
CVE-2023-54233 CVE-2023-54233: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ...
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2023-54233 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54233 CVE-2023-54233 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54233 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology contains an unsupported widget, its .module_info
field won't be set, then sof_ipc4_route_setup() will cause a kernel
Oops trying to dereference it. Add a check for such cases.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-cross-headers
rv
Sources
NVD
Debian 11, 12 No Fix Added at: Dec
Bugzilla
CVE-2023-54233 kernel: ASoC: SOF: avoid a NULL dereference with unsupported widgets
bugzilla·2025-12-30
CVE-2023-54233 [LOW] CVE-2023-54233 kernel: ASoC: SOF: avoid a NULL dereference with unsupported widgets
CVE-2023-54233 kernel: ASoC: SOF: avoid a NULL dereference with unsupported widgets
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: avoid a NULL dereference with unsupported widgets
If an IPC4 topology contains an unsupported widget, its .module_info
field won't be set, then sof_ipc4_route_setup() will cause a kernel
Oops trying to dereference it. Add a check for such cases.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123031-CVE-2023-54233-1e82@gregkh/T
2025-12-30
Published