CVE-2023-54240

Linux kernel - Null Pointer Dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix possible NULL pointer dereference in mtk_hwlro_get_fdir_all() rule_locs is allocated in ethtool_get_rxnfc and the size is determined by rule_cnt from user space. So rule_cnt needs to be check before using rule_locs to avoid NULL pointer dereference.

Scores

EPSS 0.0018
EPSS Percentile 8.2%

Details

Status published
Products (25)
linux/Kernel 4.15.0 - 4.19.295linux
linux/Kernel 4.20.0 - 5.4.257linux
linux/Kernel 4.9.0 - 4.14.326linux
linux/Kernel 5.11.0 - 5.15.132linux
linux/Kernel 5.16.0 - 6.1.54linux
linux/Kernel 5.5.0 - 5.10.195linux
linux/Kernel 6.2.0 - 6.5.4linux
Linux/Linux < 4.9
Linux/Linux 4.14.326 - 4.14.*
Linux/Linux 4.19.295 - 4.19.*
... and 15 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026