SB20250919103 - NULL pointer dereference in Linux kernel drm mediatek driver
Published: September 19, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-53389)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the mtk_dp_hpd_event_thread() function in drivers/gpu/drm/mediatek/mtk_dp.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3551789d0635dfb2df8ab8e7fdbf0647e9c1724c
- https://git.kernel.org/stable/c/36b617f7e4ae663fcadd202ea061ca695ca75539
- https://git.kernel.org/stable/c/6524d3d58797975cc40b85be1e9b89721b4e8d0b
- https://git.kernel.org/stable/c/d1c04e338016ae2517c641806a831b1f3eee2bed
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3.2