CVE-2023-54313NULL Pointer Dereference in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: ovl: fix null pointer dereference in ovl_get_acl_rcu() Following process: P1 P2 path_openat link_path_walk may_lookup inode_permission(rcu) ovl_permission acl_permission_check check_acl get_cached_acl_rcu ovl_get_inode_acl realinode = ovl_inode_real(ovl_inode) drop_cache __dentry_kill(ovl_dentry) iput(ovl_inode) ovl_destroy_inode(ovl_inode) dput(oi->__upperdentry) dentry_kill(upperdentry) dentry_unlink_inode upperdentry->d_ino

Affected Packages4 packages

Linuxlinux/linux_kernel5.15.05.15.121+2
Debianlinux/linux_kernel< 6.1.52-1+2
CVEListV5linux/linux332f606b32b6291a944c8cf23b91f53a6e676525d97481c7b2739a704848bb3c01f224dc71bdf78e+4
debiandebian/linux< linux 6.1.52-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-5fqh-8g63-525q: In the Linux kernel, the following vulnerability has been resolved: ovl: fix null pointer dereference in ovl_get_acl_rcu() Following process: P1 P22025-12-30
OSV
ovl: fix null pointer dereference in ovl_get_acl_rcu()2025-12-30
OSV
CVE-2023-54313: In the Linux kernel, the following vulnerability has been resolved: ovl: fix null pointer dereference in ovl_get_acl_rcu() Following process: P1 P2 pa2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel OverlayFS: Kernel crash via null pointer dereference in ovl_get_acl_rcu()2025-12-30
Debian
CVE-2023-54313: linux - In the Linux kernel, the following vulnerability has been resolved: ovl: fix nu...2023

🕵️Threat Intelligence

1
Wiz
CVE-2023-54313 Impact, Exploitability, and Mitigation Steps | Wiz