CVE-2023-54249
published 2025-12-30CVE-2023-54249: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Only send -ENOTCONN status if client driver is available For the STOP and…
PriorityP421medium5.3
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the STOP and RESET commands, only send the channel disconnect status
-ENOTCONN if client driver is available. Otherwise, it will result in
null pointer dereference.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.20-1 (bookworm) | linux 6.1.20-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= e827569062a804c67b51930ce83a4cb886113cb7 < 353aea15d6edbd4e69e039356a1bd3e641f7d952 | 353aea15d6edbd4e69e039356a1bd3e641f7d952 |
| linux | linux | >= e827569062a804c67b51930ce83a4cb886113cb7 < 860ad591056d7e4dc30bc130b6ec6e6d70930c85 | 860ad591056d7e4dc30bc130b6ec6e6d70930c85 |
| linux | linux | >= e827569062a804c67b51930ce83a4cb886113cb7 < e6cebcc27519dcf1652e604c73b9fd4f416987c0 | e6cebcc27519dcf1652e604c73b9fd4f416987c0 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 0 < 6.1.20-1 | 6.1.20-1 |
| linux | linux_kernel | >= 5.19.0 < 6.1.16 | 6.1.16 |
| linux | linux_kernel | >= 6.2.0 < 6.2.3 | 6.2.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6wgg-jc7h-xjpr: In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the S
ghsa_unreviewed·2025-12-30
CVE-2023-54249 GHSA-6wgg-jc7h-xjpr: In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the S
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the STOP and RESET commands, only send the channel disconnect status
-ENOTCONN if client driver is available. Otherwise, it will result in
null pointer dereference.
OSV
CVE-2023-54249: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Only send -ENOTCONN status if client driver is available For the STO
osv·2025-12-30
CVE-2023-54249 CVE-2023-54249: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Only send -ENOTCONN status if client driver is available For the STO
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Only send -ENOTCONN status if client driver is available For the STOP and RESET commands, only send the channel disconnect status -ENOTCONN if client driver is available. Otherwise, it will result in null pointer dereference.
OSV
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
osv·2025-12-30
CVE-2023-54249 bus: mhi: ep: Only send -ENOTCONN status if client driver is available
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the STOP and RESET commands, only send the channel disconnect status
-ENOTCONN if client driver is available. Otherwise, it will result in
null pointer dereference.
Red Hat
kernel: bus: mhi: ep: Only send -ENOTCONN status if client driver is available
vendor_redhat·2025-12-30
CVE-2023-54249 [MEDIUM] kernel: bus: mhi: ep: Only send -ENOTCONN status if client driver is available
kernel: bus: mhi: ep: Only send -ENOTCONN status if client driver is available
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the STOP and RESET commands, only send the channel disconnect status
-ENOTCONN if client driver is available. Otherwise, it will result in
null pointer dereference.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Li
Debian
CVE-2023-54249: linux - In the Linux kernel, the following vulnerability has been resolved: bus: mhi: e...
vendor_debian·2023
CVE-2023-54249 CVE-2023-54249: linux - In the Linux kernel, the following vulnerability has been resolved: bus: mhi: e...
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Only send -ENOTCONN status if client driver is available For the STOP and RESET commands, only send the channel disconnect status -ENOTCONN if client driver is available. Otherwise, it will result in null pointer dereference.
Scope: local
bookworm: resolved (fixed in 6.1.20-1)
bullseye: resolved
forky: resolved (fixed in 6.1.20-1)
sid: resolved (fixed in 6.1.20-1)
trixie: resolved (fixed in 6.1.20-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54249 kernel: bus: mhi: ep: Only send -ENOTCONN status if client driver is available
bugzilla·2025-12-30
CVE-2023-54249 [MEDIUM] CVE-2023-54249 kernel: bus: mhi: ep: Only send -ENOTCONN status if client driver is available
CVE-2023-54249 kernel: bus: mhi: ep: Only send -ENOTCONN status if client driver is available
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the STOP and RESET commands, only send the channel disconnect status
-ENOTCONN if client driver is available. Otherwise, it will result in
null pointer dereference.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123053-CVE-2023-54249-b2c0@gregkh/T
Wiz
CVE-2023-54249 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2023-54249 [MEDIUM] CVE-2023-54249 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54249 :
Linux Debian vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: ep: Only send -ENOTCONN status if client driver is available
For the STOP and RESET commands, only send the channel disconnect status
-ENOTCONN if client driver is available. Otherwise, it will result in
null pointer dereference.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux
linux-aws-fips
Sources
NVD
Debian 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo
2025-12-30
Published