SB20251226199 - NULL pointer dereference in Linux kernel iwlwifi pcie driver
Published: December 26, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-54053)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the iwl_pci_remove() function in drivers/net/wireless/intel/iwlwifi/pcie/drv.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0f9a1bcb94016d3a3c455a77b01f6bb06e15f6eb
- https://git.kernel.org/stable/c/0fc0d287c1e7dcb39a3b9bb0f8679cd68c2156c7
- https://git.kernel.org/stable/c/7545f21eee1356ec98581125c4dba9c4c0cc7397
- https://git.kernel.org/stable/c/b655b9a9f8467684cfa8906713d33b71ea8c8f54
- https://git.kernel.org/stable/c/dcd23aa6cc0ded7950b60ce1badb80b84045c6c0
- https://git.kernel.org/stable/c/f6f2d16c77f936041b8ac495fceabded4ec6c83c
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.244