SB2025121099 - NULL pointer dereference in Linux kernel clk xilinx driver
Published: December 10, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-53807)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the clk_wzrd_register_divider() function in drivers/clk/xilinx/clk-xlnx-clock-wizard.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/25dbdfb7b71ef8601d00c6d9a2b1a96de28b30c5
- https://git.kernel.org/stable/c/2f276dd9c0f835242836d9f6823035158ce2585c
- https://git.kernel.org/stable/c/9c632a6396505a019ea6d12b5ab45e659a542a93
- https://git.kernel.org/stable/c/b35cb0c05b8dafe23ae5e8b605a91b88bcf4aba7
- https://git.kernel.org/stable/c/f078a65ebf930f4305e3c415a8338d22391642c9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.4