CVE-2023-54299

Linux Kernel 4.19.0-6.5.2 - Null Pointer Dereference in typec_altmode_attention

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: usb: typec: bus: verify partner exists in typec_altmode_attention Some usb hubs will negotiate DisplayPort Alt mode with the device but will then negotiate a data role swap after entering the alt mode. The data role swap causes the device to unregister all alt modes, however the usb hub will still send Attention messages even after failing to reregister the Alt Mode. type_altmode_attention currently does not verify whether or not a device's altmode partner exists, which results in a NULL pointer error when dereferencing the typec_altmode and typec_altmode_ops belonging to the altmode partner. Verify the presence of a device's altmode partner before sending the Attention message to the Alt Mode driver.

Scores

EPSS 0.0018
EPSS Percentile 7.7%

Details

Status published
Products (22)
linux/Kernel 4.19.0 - 5.4.257linux
linux/Kernel 5.11.0 - 5.15.132linux
linux/Kernel 5.16.0 - 6.1.53linux
linux/Kernel 5.5.0 - 5.10.195linux
linux/Kernel 6.2.0 - 6.4.16linux
linux/Kernel 6.5.0 - 6.5.3linux
Linux/Linux < 4.19
Linux/Linux 4.19
Linux/Linux 5.10.195 - 5.10.*
Linux/Linux 5.15.132 - 5.15.*
... and 12 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026