CVE-2023-54299 is a NULL pointer dereference vulnerability in the Linux kernel's USB Type-C subsystem, specifically within the typec_altmode_attention function. This flaw occurs when a USB hub initiates a data role swap after entering DisplayPort Alt Mode, causing the device to unregister alt modes while the hub continues to send Attention messages. The absence of a check for the altmode partner's existence leads to a NULL pointer error when attempting to dereference its associated structures. The vulnerability has no assigned CVSS score, but its nature suggests a local attack vector with low complexity, potentially leading to system instability or denial of service. The FAUCET Risk Score is 7/100, indicating a low overall risk. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 4.19CNA affecteddefault affected | |
| Linux | Linux | >= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7, < 0ad6bad31da692f8d7acacab07eabe7586239ae0, >= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7, < 0d3b5fe47938e9c451466845304a2bd74e967a80, >= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7, < 1101867a1711c27d8bbe0e83136bec47f8c1ca2a, >= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7, < 38e1f2ee82bacbbfded8f1c06794a443d038d054, >= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7, < 5f71716772b88cbe0e1788f6a38d7871aff2120b, >= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7, < d49547950bf7f3480d6ca05fe055978e5f0d9e5b, >= 8a37d87d72f0c69f837229c04d2fcd7117ea57e7, < f23643306430f86e2f413ee2b986e0773e79da31CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.