SB20251226193 - NULL pointer dereference in Linux kernel mtd ubi driver
Published: December 26, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-54087)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the ubi_add_volume() function in drivers/mtd/ubi/vmt.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/234c53e57424992e657e6f4acc00d3df0983176f
- https://git.kernel.org/stable/c/2ea7195b195009ecf0046e55361f393ba96d02db
- https://git.kernel.org/stable/c/45b2c5ca4d2edae70f19fdb086bd927840c4c309
- https://git.kernel.org/stable/c/5558bcf1c58720ca6e9d6198d921cb3aa337f038
- https://git.kernel.org/stable/c/5ec4c8aca5a221756a9007deadfea92795319fee
- https://git.kernel.org/stable/c/9eccdb0760cbcb4427b5303a83a3007de998af51
- https://git.kernel.org/stable/c/c15859bfd326c10230f09cb48a17f8a35f190342
- https://git.kernel.org/stable/c/fcbc795abe7897da4b5d2a6ab5010e36774b00c2
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.173