NULL pointer dereference in Linux kernel - CVE-2023-54010
Published: December 26, 2025 / Updated: December 31, 2025
Vulnerability identifier: #VU120481
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-54010
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the acpi_db_display_objects() function in drivers/acpi/acpica/dbnames.c. A local user can perform a denial of service (DoS) attack.
How to mitigate CVE-2023-54010
Install update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/35d67ffad6f5d78dbd800d354f5334c7b71a19e0
- https://git.kernel.org/stable/c/978e0d05547ae707d51a942fc7e85a34e181ee6f
- https://git.kernel.org/stable/c/ae5a0eccc85fc960834dd66e3befc2728284b86c
- https://git.kernel.org/stable/c/c409eb45f5ddae2e3b3faa76cefc87f3cd0d0e88
- https://git.kernel.org/stable/c/c9fcb2cfcbd4d7018d9f659f5b670f5b727d1968
- https://git.kernel.org/stable/c/d997c920a5305b37f0b8a40501b5aca10d099ecd
- https://git.kernel.org/stable/c/ed2e1e85644ca3d351324e9927a538c8af4df654
- https://git.kernel.org/stable/c/fee6133490091492dc66bcf71479bd53bd17a7d2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.30