CVE-2023-23000: Null Pointer Dereference
Published Mar 1, 2023
·Updated
In the Linux kernel before 5.17, drivers/phy/tegra/xusb.c mishandles the tegraxusbfindportnode return value. Callers expect NULL in the error case, but an error pointer is used.
Affected Software
2 affected componentsFixes available
Linux Linux kernel<5.17
debian/linux<=5.10.223-1, <=5.10.234-1
6.1.129-16.1.135-16.12.25-16.12.27-1
Remediation
Patch Available
Event History
Mar 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 19, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Apr 27, 2025
Data Sourced
via Ubuntu·01:21 AM
RemedyDescriptionSeverityAffected Software
May 9, 2025
Data Sourced
via Debian·01:24 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Linux kernel vulnerability?
The vulnerability ID for this Linux kernel vulnerability is CVE-2023-23000.
2
What is the severity of CVE-2023-23000?
The severity of CVE-2023-23000 is medium with a severity value of 5.5.
3
What is the affected software for CVE-2023-23000?
The affected software for CVE-2023-23000 is the Linux kernel before 5.17.
4
How can I fix CVE-2023-23000?
To fix CVE-2023-23000, update your Linux kernel version to 5.17 or later.
5
Where can I find more information about CVE-2023-23000?
More information about CVE-2023-23000 can be found at the following references: [link1], [link2], [link3].