CVE-2023-54279

Linux kernel - Null Pointer Dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: MIPS: fw: Allow firmware to pass a empty env fw_getenv will use env entry to determine style of env, however it is legal for firmware to just pass a empty list. Check if first entry exist before running strchr to avoid null pointer dereference.

Scores

EPSS 0.0020
EPSS Percentile 10.5%

Details

Status published
Products (28)
linux/Kernel 3.10.0 - 4.14.315linux
linux/Kernel 4.15.0 - 4.19.283linux
linux/Kernel 4.20.0 - 5.4.243linux
linux/Kernel 5.11.0 - 5.15.111linux
linux/Kernel 5.16.0 - 6.1.28linux
linux/Kernel 5.5.0 - 5.10.180linux
linux/Kernel 6.2.0 - 6.2.15linux
linux/Kernel 6.3.0 - 6.3.2linux
Linux/Linux < 3.10
Linux/Linux 14aecdd419217e041fb5dd2749d11f58503bdf62 - 0f91290774c798199ba4b8df93de5c3156b5163d
... and 18 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026