CVE-2023-54233: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.

Affected products

  • Linux Linux: from 6.0, before 6.1.189 (fixed in 6.1.189); from 6.2, before 6.2.11 (fixed in 6.2.11)

Published 2025-12-30. Last modified 2026-10-03.