#VU120766 NULL pointer dereference in Linux kernel - CVE-2023-54279
Published: December 30, 2025 / Updated: December 30, 2025
Vulnerability identifier: #VU120766
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-54279
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the fw_getenv() function in arch/mips/fw/lib/cmdline.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/0f91290774c798199ba4b8df93de5c3156b5163d
- https://git.kernel.org/stable/c/3ef93b7bd9e042db240843f24a80e14da38c6830
- https://git.kernel.org/stable/c/47e61cadc7a5f3dffd42d2d6fda81be163f1ab82
- https://git.kernel.org/stable/c/830181ddced5a05a711dc9da8043203b1f33a77e
- https://git.kernel.org/stable/c/a6b54af407873227caef6262e992f5422cdcb6ae
- https://git.kernel.org/stable/c/ad79828f133e98585ab2236cad04a55eb7141bbe
- https://git.kernel.org/stable/c/aeed787bbbbe1b842beec9a065a36c915226f704
- https://git.kernel.org/stable/c/ee1809ed7bc456a72dc8410b475b73021a3a68d5
- https://git.kernel.org/stable/c/f334b31625683418aaa2a335470eec950a95a254
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.315