CVE-2023-54049
NULL Pointer Dereference in Linux rpmsg: glink Due to Missing kstrdup Check
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: kernel.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in the Linux kernel's rpmsg: glink component occurs because the code did not check the return value of the kstrdup() function. If kstrdup() fails and returns NULL, the code could dereference this NULL pointer, leading to a potential crash or undefined behavior. The fix adds a check for kstrdup()'s return value and returns an error if it fails, preventing the NULL pointer dereference.
How can this vulnerability impact me? :
If exploited, this vulnerability could cause the Linux kernel to dereference a NULL pointer, potentially leading to a system crash or instability. This could result in denial of service or unexpected behavior in systems using the affected rpmsg: glink component.