PT-2025-54108 · Linux · Linux Kernel

CVE-2023-54279

·

Publicado

2023-04-12

·

Atualizado

2025-12-31

CVSS v2.0

5.5

Média

VetorAV:A/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the firmware handling mechanism. Specifically, the fw getenv function does not properly validate the environment list passed by the firmware, potentially leading to a null pointer dereference if an empty list is provided. This occurs because the function attempts to access the first entry of the environment list without checking if the list is empty.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04174
CVE-2023-54279

Produtos afetados

Linux Kernel