SB2025102350 - NULL pointer dereference in Linux kernel drm stm driver
Published: October 23, 2025 Updated: October 26, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-53714)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the ltdc_crtc_disable_vblank() function in drivers/gpu/drm/stm/ltdc.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04fe3b82528232aa85a6c45464906d0727ef4f20
- https://git.kernel.org/stable/c/340dba127bbed51e8425cd8e097aacfadd175462
- https://git.kernel.org/stable/c/898a9e3f56db9860ab091d4bf41b6caa99aafc3d
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.47
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5