
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53864 is a NULL pointer dereference vulnerability in the Linux kernel's drm/mxsfb DRM driver. The flaw occurs in the mxsfb_plane_overlay_atomic_update() function, where the overlay plane's framebuffer pointer can be NULL during a disable operation, causing a kernel Oops when dereferenced. It was published on December 9, 2025, and affects Linux kernel versions from commit cb285a5348e768dbc8edfe28cc2be5ec0c7e1a33 up to the patched releases in stable branches 6.1.54, 6.5.4, and 6.6. The CVSS category is estimated as Medium, with an EPSS score of 0.000170 (Feedly, ENISA EUVD).
The root cause is a NULL pointer dereference (CWE-476) in the mxsfb_plane_overlay_atomic_update() function of the Linux kernel's drm/mxsfb display driver. When the overlay plane is being disabled, the function is called with a NULL framebuffer pointer; dereferencing this pointer triggers a kernel Oops. The fix relocates the disable logic to mxsfb_plane_overlay_atomic_disable(), which is the appropriate callback for handling plane disablement and avoids the NULL dereference. Exploitation requires local access to a system using the MXSFB display controller (common in NXP i.MX SoC-based embedded/IoT devices) (Feedly, Kernel Git).
Successful triggering of this vulnerability causes a kernel Oops (NULL pointer dereference), which typically results in a kernel panic and system crash, impacting availability. There is no evidence of confidentiality or integrity impact, and the vulnerability is limited to systems using the MXSFB DRM driver (NXP i.MX-based platforms). The scope is confined to the local system; lateral movement or data exfiltration are not associated with this vulnerability (Feedly).
The Linux kernel maintainers have addressed this vulnerability in stable branches with the following patch commits: 8bf2d4ca521d3acb57fc1607386e749b3cc92aaf (mainline/6.6), 0f98de0a11d29821d9448114178ddc1b1fe32a18 (6.5.4), and aa656d48e871a1b062e1bbf9474d8b831c35074c (6.1.54). Users running affected kernel versions on NXP i.MX-based systems should update to kernel 6.1.54, 6.5.4, 6.6, or later. SUSE has also issued advisories incorporating this fix for their enterprise kernel packages (Feedly, Linux Security SUSE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."