PT-2025-54108 · Linux · Linux Kernel

Published

2023-04-12

·

Updated

2025-12-31

·

CVE-2023-54279

CVSS v2.0

5.5

Medium

VectorAV:A/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in the firmware handling mechanism. Specifically, the fw getenv function does not properly validate the environment list passed by the firmware, potentially leading to a null pointer dereference if an empty list is provided. This occurs because the function attempts to access the first entry of the environment list without checking if the list is empty.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-04174
CVE-2023-54279

Affected Products

Linux Kernel