CVE-2023-53864
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-53864 is a NULL pointer dereference vulnerability in the Linux kernel's drm/mxsfb DRM driver. The flaw occurs in the mxsfb_plane_overlay_atomic_update() function, where the overlay plane's framebuffer pointer can be NULL during a disable operation, causing a kernel Oops when dereferenced. It was published on December 9, 2025, and affects Linux kernel versions from commit cb285a5348e768dbc8edfe28cc2be5ec0c7e1a33 up to the patched releases in stable branches 6.1.54, 6.5.4, and 6.6. The CVSS category is estimated as Medium, with an EPSS score of 0.000170 (Feedly, ENISA EUVD).

Technical details

The root cause is a NULL pointer dereference (CWE-476) in the mxsfb_plane_overlay_atomic_update() function of the Linux kernel's drm/mxsfb display driver. When the overlay plane is being disabled, the function is called with a NULL framebuffer pointer; dereferencing this pointer triggers a kernel Oops. The fix relocates the disable logic to mxsfb_plane_overlay_atomic_disable(), which is the appropriate callback for handling plane disablement and avoids the NULL dereference. Exploitation requires local access to a system using the MXSFB display controller (common in NXP i.MX SoC-based embedded/IoT devices) (Feedly, Kernel Git).

Impact

Successful triggering of this vulnerability causes a kernel Oops (NULL pointer dereference), which typically results in a kernel panic and system crash, impacting availability. There is no evidence of confidentiality or integrity impact, and the vulnerability is limited to systems using the MXSFB DRM driver (NXP i.MX-based platforms). The scope is confined to the local system; lateral movement or data exfiltration are not associated with this vulnerability (Feedly).

Mitigation and workarounds

The Linux kernel maintainers have addressed this vulnerability in stable branches with the following patch commits: 8bf2d4ca521d3acb57fc1607386e749b3cc92aaf (mainline/6.6), 0f98de0a11d29821d9448114178ddc1b1fe32a18 (6.5.4), and aa656d48e871a1b062e1bbf9474d8b831c35074c (6.1.54). Users running affected kernel versions on NXP i.MX-based systems should update to kernel 6.1.54, 6.5.4, 6.6, or later. SUSE has also issued advisories incorporating this fix for their enterprise kernel packages (Feedly, Linux Security SUSE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management