CVE-2023-54087

Linux Kernel - Null Pointer Dereference in ubi_free_volume()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ubi: Fix possible null-ptr-deref in ubi_free_volume() It willl cause null-ptr-deref in the following case: uif_init() ubi_add_volume() cdev_add() -> if it fails, call kill_volumes() device_register() kill_volumes() -> if ubi_add_volume() fails call this function ubi_free_volume() cdev_del() device_unregister() -> trying to delete a not added device, it causes null-ptr-deref So in ubi_free_volume(), it delete devices whether they are added or not, it will causes null-ptr-deref. Handle the error case whlie calling ubi_add_volume() to fix this problem. If add volume fails, set the corresponding vol to null, so it can not be accessed in kill_volumes() and release the resource in ubi_add_volume() error path.

Scores

EPSS 0.0019
EPSS Percentile 9.1%

Details

Status published
Products (25)
linux/Kernel 2.6.22 - 4.14.308linux
linux/Kernel 4.15.0 - 4.19.276linux
linux/Kernel 4.20.0 - 5.4.235linux
linux/Kernel 5.11.0 - 5.15.100linux
linux/Kernel 5.16.0 - 6.1.18linux
linux/Kernel 5.5.0 - 5.10.173linux
linux/Kernel 6.2.0 - 6.2.5linux
Linux/Linux < 2.6.22
Linux/Linux 2.6.22
Linux/Linux 4.14.308 - 4.14.*
... and 15 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026