CVE-2023-54233

low

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: avoid a NULL dereference with unsupported widgets If an IPC4 topology contains an unsupported widget, its .module_info field won't be set, then sof_ipc4_route_setup() will cause a kernel Oops trying to dereference it. Add a check for such cases.

References

https://git.kernel.org/stable/c/e3720f92e0237921da537e47a0b24e27899203f8

https://git.kernel.org/stable/c/d42fe2721111138d7656d4f621f38c171979c8a0

https://git.kernel.org/stable/c/170818974e9732506195c6302743856cc8bdfd6f

https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-60408

Details

Source: Mitre, NVD

Published: 2025-12-30

Updated: 2026-10-03

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Low

EPSS

EPSS: 0.00018