Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-54264

Опубликовано: 30 дек. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: fs/sysv: Null check to prevent null-ptr-deref bug sb_getblk(inode->i_sb, parent) return a null ptr and taking lock on that leads to the null-ptr-deref bug.

A NULL pointer dereference vulnerability was found in the Linux kernel's System V filesystem (sysv). The code fails to check if sb_getblk() returns NULL before attempting to take a lock on the returned buffer head. When sb_getblk() fails and returns NULL, the subsequent lock operation dereferences the NULL pointer, causing a kernel crash.

Отчет

This flaw affects systems mounting System V (sysv) filesystems. The NULL pointer dereference occurs when the kernel fails to allocate a buffer block during filesystem operations. While sysv is a legacy filesystem format rarely used in modern systems, mounting a crafted or corrupted sysv filesystem image could trigger this crash.

Меры по смягчению последствий

To mitigate this issue, prevent the sysv module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2426018kernel: fs/sysv: Null check to prevent null-ptr-deref bug

EPSS

Процентиль: 11%
0.00206
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: fs/sysv: Null check to prevent null-ptr-deref bug sb_getblk(inode->i_sb, parent) return a null ptr and taking lock on that leads to the null-ptr-deref bug.

nvd
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: fs/sysv: Null check to prevent null-ptr-deref bug sb_getblk(inode->i_sb, parent) return a null ptr and taking lock on that leads to the null-ptr-deref bug.

debian
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: f ...

CVSS3: 5.5
redos
2 месяца назад

Уязвимость kernel-lt

github
8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: fs/sysv: Null check to prevent null-ptr-deref bug sb_getblk(inode->i_sb, parent) return a null ptr and taking lock on that leads to the null-ptr-deref bug.

EPSS

Процентиль: 11%
0.00206
Низкий

5.5 Medium

CVSS3