CVE-2023-53220

Source
https://cve.org/CVERecord?id=CVE-2023-53220
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53220.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-53220
Downstream
Related
Published
2025-09-15T14:21:49.075Z
Modified
2026-04-11T12:46:42.971851Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
media: az6007: Fix null-ptr-deref in az6007_i2c_xfer()
Details

In the Linux kernel, the following vulnerability has been resolved:

media: az6007: Fix null-ptr-deref in az6007i2cxfer()

In az6007i2cxfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach az6007i2cxfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash.

Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027i2cxfer()")

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53220.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
caa1a700ed2a06a831e6a7db5d9f213fc63caee3
Fixed
c6763fefa267f6e62595a6ac1f57815d99fc90b7
Fixed
adcb73f8ce9aec48b1f85223f401c1574015d8d2
Fixed
991c77fe18c6f374bbf83376f8c42550aa565662
Fixed
a9def3e9718a4dc756f48db147d42ec41a966240
Fixed
5b1ea100ad3695025969dc4693f307877fb688d6
Fixed
6ab7ea4e17d6a605d05308adf8f3408924770cba
Fixed
a1110f19d4940e4185251d072cbb0ff51486a1e7
Fixed
1047f9343011f2cedc73c64829686206a7e9fc3f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53220.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4.0
Fixed
4.14.326
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.295
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.257
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.197
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.133
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.55
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.5.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-53220.json"