cbcvebase.
CVE-2023-54233
published 2025-12-30

CVE-2023-54233: In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains…

PriorityP418low3.3
EPSS
0.16%
5.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.3.7-1 (forky)linux 6.3.7-1 (forky)
linuxlinux
linuxlinux>= 3acd527089463742a3dd95e274d53c2fdd834716 < 170818974e9732506195c6302743856cc8bdfd6f170818974e9732506195c6302743856cc8bdfd6f
linuxlinux>= 3acd527089463742a3dd95e274d53c2fdd834716 < e3720f92e0237921da537e47a0b24e27899203f8e3720f92e0237921da537e47a0b24e27899203f8
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 6.0.0 < 6.2.116.2.11
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.