CVE-2023-53250 - CVE House
Back to Database
Status published Unknown CVE-2023-53250

firmware: dmi-sysfs: Fix null-ptr-deref in dmi_sysfs_register_handle

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: firmware: dmi-sysfs: Fix null-ptr-deref in dmi_sysfs_register_handle KASAN reported a null-ptr-deref error: KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 PID: 1373 Comm: modprobe Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) RIP: 0010:dmi_sysfs_entry_release ... Call Trace: <TASK> kobject_put dmi_sysfs_register_handle (drivers/firmware/dmi-sysfs.c:540) dmi_sysfs dmi_decode_table (drivers/firmware/dmi_scan.c:133) dmi_walk (drivers/firmware/dmi_scan.c:1115) dmi_sysfs_init (drivers/firmware/dmi-sysfs.c:149) dmi_sysfs do_one_initcall (init/main.c:1296) ... Kernel panic - not syncing: Fatal exception Kernel Offset: 0x4000000 from 0xffffffff81000000 ---[ end Kernel panic - not syncing: Fatal exception ]--- It is because previous patch added kobject_put() to release the memory which will call dmi_sysfs_entry_release() and list_del(). However, list_add_tail(entry->list) is called after the error block, so the list_head is uninitialized and cannot be deleted. Move error handling to after list_add_tail to fix this.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53250

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
fdffa4ad8f6bf1ece877edfb807f2b2c729d8578, 660ba678f9998aca6db74f2dd912fa5124f0fa31, a9bfb37d6ba7c376b0d53337a4c5f5ff324bd725, ed38d04342dfbe9e5aca745c8b5eb4188a74f0ef, c66cc3c62870a27ea8f060a7e4c1ad8d26dd3f0d, a724634b2a49f6ff0177a9e19a5a92fc1545e1b7, 985706bd3bbeffc8737bc05965ca8d24837bc7db, 3ba359ebe914ac3f8c6c832b28007c14c39d3766, ec752973aa721ee281d5441e497364637c626c7b, 5.15.47, 4.9.318, 4.14.283, 4.19.247, 5.4.198, 5.10.122, 5.17.15, 5.18.4, 5.19, 0, 5.15.99, 6.1.16, 6.2.3, 6.3

Timeline

Official Publish: September 15th, 2025
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.