CVE Database
/

CVE-2023-54279

Back to search

CVE-2023-54279

Published: Dec 30, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: MIPS: fw: Allow firmware to pass a empty env fw_getenv will use env entry to determine style of env, however it is legal for firmware to just pass a empty list. Check if first entry exist before running strchr to avoid null pointer dereference.

VendorProductVersions

Linux

Linux

affected
14aecdd419217e041fb5dd2749d11f58503bdf62 - < f334b31625683418aaa2a335470eec950a95a254
affected
14aecdd419217e041fb5dd2749d11f58503bdf62 - < 830181ddced5a05a711dc9da8043203b1f33a77e
affected
14aecdd419217e041fb5dd2749d11f58503bdf62 - < 0f91290774c798199ba4b8df93de5c3156b5163d
affected
14aecdd419217e041fb5dd2749d11f58503bdf62 - < 47e61cadc7a5f3dffd42d2d6fda81be163f1ab82
affected
14aecdd419217e041fb5dd2749d11f58503bdf62 - < 3ef93b7bd9e042db240843f24a80e14da38c6830

+4 more versions

Linux

Linux

affected
3.10
unaffected
0 - < 3.10
unaffected
4.14.315 - <= 4.14.*
unaffected
4.19.283 - <= 4.19.*
unaffected
5.4.243 - <= 5.4.*

+6 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now