CVE-2023-53220

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-53220
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53220.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53220
Downstream
Published
2025-09-15T15:15:48Z
Modified
2025-09-15T20:01:26Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

media: az6007: Fix null-ptr-deref in az6007i2cxfer()

In az6007i2cxfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach az6007i2cxfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash.

Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027i2cxfer()")

References

Affected packages