Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-54093— media: anysee: fix null-ptr-deref in anysee_master_xfer

AI Predicted 6.5 Difficulty: Moderate EPSS 0.20% · P10

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinuxa51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< 73c0b224ceeba12dee2a7a8cbc147648da0b2e63affected
a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< e04affec2506ff5c12a18d78d7e694b3556a8982affected
a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< 8dc5b370254abc10f0cb4141d90cecf7ce465472affected
a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< 4a9763d2bc4a6d6fab42555b9c0b2eefa32585acaffected
a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< 3dd5846a873938ec7b6d404ec27662942cd8f2efaffected
a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< 14b94154a72388b57221a2a73795c0ea61a95373affected
a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< 5975dbbb7ad0767eaabd15d2c37a739ac76acb00affected
a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b< c30411266fd67ea3c02a05c157231654d5a3bdc9affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-54093

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
media: anysee: fix null-ptr-deref in anysee_master_xfer
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: anysee: fix null-ptr-deref in anysee_master_xfer In anysee_master_xfer, msg is controlled by user. When msg[i].buf is null and msg[i].len is zero, former checks on msg[i].buf would be passed. Malicious data finally reach anysee_master_xfer. If accessing msg[i].buf[0] without sanity check, null ptr deref would happen. We add check on msg[i].len to prevent crash. Similar commit: commit 0ed554fd769a ("media: dvb-usb: az6027: fix null-ptr-deref in az6027_i2c_xfer()") [hverkuil: add spaces around +]
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于anysee_master_xfer函数缺少对msg[i].len的检查,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux a51e34dd6080d8d5c9e95a4e0292cd4cb889a61b ~ 73c0b224ceeba12dee2a7a8cbc147648da0b2e63 -
LinuxLinux 2.6.27 -

II. Public POCs for CVE-2023-54093

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-54093

登录查看更多情报信息。

Other References for CVE-2023-54093 (2)

Same Patch Batch · Linux · 2025-12-24 · 322 CVEs total

CVE-2023-540769.8 CRITICALsmb: client: fix missed ses refcounting
CVE-2022-507179.8 CRITICALnvmet-tcp: add bounds check on Transfer Tag
CVE-2025-687459.8 CRITICALscsi: qla2xxx: Clear cmds after chip reset
CVE-2025-687419.8 CRITICALscsi: qla2xxx: Fix improper freeing of purex item
CVE-2023-540909.8 CRITICALixgbe: Fix panic during XDP_TX with > 64 CPUs
CVE-2023-540949.8 CRITICALnet: prevent skb corruption on frag list segmentation
CVE-2023-538679.8 CRITICALceph: fix potential use-after-free bug when trimming caps
CVE-2025-683599.8 CRITICALbtrfs: fix double free of qgroup record after failure to add delayed ref head
CVE-2025-687269.8 CRITICALcrypto: aead - Fix reqsize handling
CVE-2023-539969.3 CRITICALx86/sev: Make enc_dec_hypercall() accept a size instead of npages
CVE-2023-540718.8 HIGHwifi: rtw88: use work to update rate to avoid RCU warning
CVE-2023-540608.8 HIGHiommufd: Set end correctly when doing batch carry
CVE-2023-540438.8 HIGHiommufd: Do not add the same hwpt to the ioas->hwpt_list twice
CVE-2022-507328.8 HIGHstaging: rtl8192u: Fix use after free in ieee80211_rx()
CVE-2025-687368.8 HIGHlandlock: Fix handling of disconnected directories
CVE-2023-540408.8 HIGHice: fix wrong fallback logic for FDIR
CVE-2023-540928.8 HIGHKVM: s390: pv: fix index value of replaced ASCE
CVE-2023-541208.8 HIGHBluetooth: Fix race condition in hidp_session_thread
CVE-2023-539868.6 HIGHmips: bmips: BCM6358: disable RAC flush for TP1
CVE-2022-507468.4 HIGHerofs: validate the extent length for uncompressed pclusters

Showing top 20 of 322 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-54093

No comments yet


Leave a comment