CVE-2023-54240

Source
https://cve.org/CVERecord?id=CVE-2023-54240
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-54240.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-54240
Downstream
Related
Published
2025-12-30T12:11:29.039Z
Modified
2026-03-31T17:29:40.603026099Z
Summary
net: ethernet: mtk_eth_soc: fix possible NULL pointer dereference in mtk_hwlro_get_fdir_all()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: mtkethsoc: fix possible NULL pointer dereference in mtkhwlrogetfdirall()

rulelocs is allocated in ethtoolgetrxnfc and the size is determined by rulecnt from user space. So rulecnt needs to be check before using rulelocs to avoid NULL pointer dereference.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54240.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7aab747e5563ecbc9f3cb64ddea13fe7b9fee2bd
Fixed
7776591e5ae2befff86579f68916a171971c6aab
Fixed
751b2e22a188b0c306029d094da29b6b8de31430
Fixed
653fbddbdfc6673bba01b13dae5a4384ad8f92ec
Fixed
75f2de75c1182e80708c932418e4895dbc88b68f
Fixed
072324cfab9b96071c0782f51f53cc5aea1e9d5b
Fixed
ff5faed5f5487b0fd2b640ba1304f82a5ebaab42
Fixed
fe0195fe48f85182bc7e7eabcad925bd3cbc10f5
Fixed
e4c79810755f66c9a933ca810da2724133b1165a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-54240.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.9.0
Fixed
4.14.326
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.295
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.257
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.195
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.132
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.54
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.5.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-54240.json"