CVE-2023-54248
published 2025-12-30CVE-2023-54248: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add check for kmemdup Since the kmemdup may return NULL pointer, it should be…
PriorityP417
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it should be better to add check for the return value
in order to avoid NULL pointer dereference.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.37-1 (bookworm) | linux 6.1.37-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b46acd6a6a627d876898e1c84d3f84902264b445 < 952bbfcedbf895963509861e55a6e4fc105eb842 | 952bbfcedbf895963509861e55a6e4fc105eb842 |
| linux | linux | >= b46acd6a6a627d876898e1c84d3f84902264b445 < 7898db22ed6cee909513cf4935b5f9f0298b74f0 | 7898db22ed6cee909513cf4935b5f9f0298b74f0 |
| linux | linux | >= b46acd6a6a627d876898e1c84d3f84902264b445 < 9f36704a58adade3b0216f8a3fa5503db4517208 | 9f36704a58adade3b0216f8a3fa5503db4517208 |
| linux | linux | >= b46acd6a6a627d876898e1c84d3f84902264b445 < cdcdfd57f4c701f832787da1309cc6687917d783 | cdcdfd57f4c701f832787da1309cc6687917d783 |
| linux | linux | >= b46acd6a6a627d876898e1c84d3f84902264b445 < e6c3cef24cb0d045f99d5cb039b344874e3cfd74 | e6c3cef24cb0d045f99d5cb039b344874e3cfd74 |
| linux | linux_kernel | >= 0 < 6.1.37-1 | 6.1.37-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 0 < 6.3.7-1 | 6.3.7-1 |
| linux | linux_kernel | >= 5.15.0 < 5.15.111 | 5.15.111 |
| linux | linux_kernel | >= 5.16.0 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 6.2.0 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3.0 < 6.3.2 | 6.3.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jf6q-v9m6-wc7j: In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it sh
ghsa_unreviewed·2025-12-30
CVE-2023-54248 GHSA-jf6q-v9m6-wc7j: In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it sh
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it should be better to add check for the return value
in order to avoid NULL pointer dereference.
OSV
CVE-2023-54248: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add check for kmemdup Since the kmemdup may return NULL pointer, it shou
osv·2025-12-30
CVE-2023-54248 CVE-2023-54248: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add check for kmemdup Since the kmemdup may return NULL pointer, it shou
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add check for kmemdup Since the kmemdup may return NULL pointer, it should be better to add check for the return value in order to avoid NULL pointer dereference.
OSV
fs/ntfs3: Add check for kmemdup
osv·2025-12-30
CVE-2023-54248 fs/ntfs3: Add check for kmemdup
fs/ntfs3: Add check for kmemdup
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it should be better to add check for the return value
in order to avoid NULL pointer dereference.
Red Hat
kernel: fs/ntfs3: Add check for kmemdup
vendor_redhat·2025-12-30
CVE-2023-54248 kernel: fs/ntfs3: Add check for kmemdup
kernel: fs/ntfs3: Add check for kmemdup
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it should be better to add check for the return value
in order to avoid NULL pointer dereference.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2023-54248: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: A...
vendor_debian·2023
CVE-2023-54248 CVE-2023-54248: linux - In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: A...
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add check for kmemdup Since the kmemdup may return NULL pointer, it should be better to add check for the return value in order to avoid NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 6.1.37-1)
bullseye: resolved
forky: resolved (fixed in 6.3.7-1)
sid: resolved (fixed in 6.3.7-1)
trixie: resolved (fixed in 6.3.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54248 kernel: fs/ntfs3: Add check for kmemdup
bugzilla·2025-12-30
CVE-2023-54248 CVE-2023-54248 kernel: fs/ntfs3: Add check for kmemdup
CVE-2023-54248 kernel: fs/ntfs3: Add check for kmemdup
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it should be better to add check for the return value
in order to avoid NULL pointer dereference.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123053-CVE-2023-54248-c2cf@gregkh/T
Wiz
CVE-2023-54248 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54248 CVE-2023-54248 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54248 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Add check for kmemdup
Since the kmemdup may return NULL pointer,
it should be better to add check for the return value
in order to avoid NULL pointer dereference.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux-oracle-5.15
bpftool
Sources
NVD
Debian 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo Has Fix Added at: Dec 31, 2025
Ubuntu 16.04, 18.04 Severity
https://git.kernel.org/stable/c/7898db22ed6cee909513cf4935b5f9f0298b74f0https://git.kernel.org/stable/c/952bbfcedbf895963509861e55a6e4fc105eb842https://git.kernel.org/stable/c/9f36704a58adade3b0216f8a3fa5503db4517208https://git.kernel.org/stable/c/cdcdfd57f4c701f832787da1309cc6687917d783https://git.kernel.org/stable/c/e6c3cef24cb0d045f99d5cb039b344874e3cfd74
2025-12-30
Published