SB20251230207 - NULL pointer dereference in Linux kernel kvm svm
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-54296)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the sev_migrate_from() function in arch/x86/kvm/svm/sev.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2ee4b180d51b12a45bdd3264629719ef6a572a73
- https://git.kernel.org/stable/c/5c18ace750e4d4d58d7da02d1c669bf21c824158
- https://git.kernel.org/stable/c/f1187ef24eb8f36e8ad8106d22615ceddeea6097
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.54
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.5.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6