SB20251230218 - NULL pointer dereference in Linux kernel mhi ep driver
Published: December 30, 2025 Updated: December 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2023-54249)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the mhi_ep_process_cmd_ring() function in drivers/bus/mhi/ep/main.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/353aea15d6edbd4e69e039356a1bd3e641f7d952
- https://git.kernel.org/stable/c/860ad591056d7e4dc30bc130b6ec6e6d70930c85
- https://git.kernel.org/stable/c/e6cebcc27519dcf1652e604c73b9fd4f416987c0
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.3
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3