CVE-2023-54233

Linux Kernel 6.0-6.2.10 - Denial of Service via NULL Pointer Dereference in ASoC SOF Widget Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.

Scores

EPSS 0.0016
EPSS Percentile 5.8%

Details

Status published
Products (7)
linux/Kernel 6.0.0 - 6.2.11linux
Linux/Linux < 6.0
Linux/Linux 3acd527089463742a3dd95e274d53c2fdd834716 - 170818974e9732506195c6302743856cc8bdfd6f
Linux/Linux 3acd527089463742a3dd95e274d53c2fdd834716 - e3720f92e0237921da537e47a0b24e27899203f8
Linux/Linux 6.0
Linux/Linux 6.2.11 - 6.2.*
Linux/Linux 6.3
Published Dec 30, 2025
Tracked Since Feb 18, 2026