vulnerability
Ubuntu: (CVE-2023-53244): linux vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | Sep 16, 2025 | Sep 19, 2025 | Jun 17, 2026 |
Description
In the Linux kernel, the following vulnerability has been resolved:
media: pci: tw68: Fix null-ptr-deref bug in buf prepare and finish
When the driver calls tw68_risc_buffer() to prepare the buffer, the
function call dma_alloc_coherent may fail, resulting in a empty buffer
buf->cpu. Later when we free the buffer or access the buffer, null ptr
deref is triggered.
This bug is similar to the following one:
https://git.linuxtv.org/media_stage.git/commit/?id=2b064d91440b33fba5b452f2d1b31f13ae911d71.
We believe the bug can be also dynamically triggered from user side.
Similarly, we fix this by checking the return value of tw68_risc_buffer()
and the value of buf->cpu before buffer free.
Solutions
References
- CVE-2023-53244
- https://attackerkb.com/topics/CVE-2023-53244
- CWE-476
- EUVD-EUVD-2023-59840
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59840
- https://git.kernel.org/linus/1634b7adcc5bef645b3666fdd564e5952a9e24e0
- https://git.kernel.org/stable/c/1634b7adcc5bef645b3666fdd564e5952a9e24e0
- https://git.kernel.org/stable/c/3715c5e9a8f96b6ed0dcbea06da443efccac1ecc
- https://git.kernel.org/stable/c/3c67f49a6643d973e83968ea35806c7b5ae68b56
- https://git.kernel.org/stable/c/dcf632bca424e6ff8c8eb89c96694e7f05cd29b6
- https://www.cve.org/CVERecord?id=CVE-2023-53244
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.