cbcvebase.
CVE-2023-54279
published 2025-12-30

CVE-2023-54279: In the Linux kernel, the following vulnerability has been resolved: MIPS: fw: Allow firmware to pass a empty env fw_getenv will use env entry to determine…

PriorityP421medium5.3
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved: MIPS: fw: Allow firmware to pass a empty env fw_getenv will use env entry to determine style of env, however it is legal for firmware to just pass a empty list. Check if first entry exist before running strchr to avoid null pointer dereference.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.37-1 (bookworm)linux 6.1.37-1 (bookworm)
linuxlinux
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < f334b31625683418aaa2a335470eec950a95a254f334b31625683418aaa2a335470eec950a95a254
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < 830181ddced5a05a711dc9da8043203b1f33a77e830181ddced5a05a711dc9da8043203b1f33a77e
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < 0f91290774c798199ba4b8df93de5c3156b5163d0f91290774c798199ba4b8df93de5c3156b5163d
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < 47e61cadc7a5f3dffd42d2d6fda81be163f1ab8247e61cadc7a5f3dffd42d2d6fda81be163f1ab82
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < 3ef93b7bd9e042db240843f24a80e14da38c68303ef93b7bd9e042db240843f24a80e14da38c6830
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < a6b54af407873227caef6262e992f5422cdcb6aea6b54af407873227caef6262e992f5422cdcb6ae
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < ad79828f133e98585ab2236cad04a55eb7141bbead79828f133e98585ab2236cad04a55eb7141bbe
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < aeed787bbbbe1b842beec9a065a36c915226f704aeed787bbbbe1b842beec9a065a36c915226f704
linuxlinux>= 14aecdd419217e041fb5dd2749d11f58503bdf62 < ee1809ed7bc456a72dc8410b475b73021a3a68d5ee1809ed7bc456a72dc8410b475b73021a3a68d5
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.37-16.1.37-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 0 < 6.3.7-16.3.7-1
linuxlinux_kernel>= 3.10.0 < 4.14.3154.14.315
linuxlinux_kernel>= 4.15.0 < 4.19.2834.19.283
linuxlinux_kernel>= 4.20.0 < 5.4.2435.4.243
linuxlinux_kernel>= 5.11.0 < 5.15.1115.15.111
linuxlinux_kernel>= 5.16.0 < 6.1.286.1.28
linuxlinux_kernel>= 5.5.0 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2.0 < 6.2.156.2.15
linuxlinux_kernel>= 6.3.0 < 6.3.26.3.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.