
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-54299 is a NULL pointer dereference vulnerability in the Linux kernel's USB Type-C Alt Mode bus driver (typec_altmode_attention). It affects Linux kernel versions from commit 8a37d87d72f0 up to multiple stable branch fix points, spanning kernel versions 4.19 through pre-6.6. The vulnerability was published on December 30, 2025, and has a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).
The root cause is a missing NULL pointer check (CWE-476) in the typec_altmode_attention() function within the Linux kernel's USB Type-C bus driver (drivers/usb/typec/bus.c). When a USB hub negotiates DisplayPort Alt mode with a connected device and subsequently performs a data role swap, the device unregisters all Alt modes. However, the hub continues to send Attention messages; typec_altmode_attention does not verify whether the Alt Mode partner still exists before dereferencing typec_altmode and typec_altmode_ops structures, resulting in a NULL pointer dereference. The fix adds a partner existence check before forwarding the Attention message to the Alt Mode driver (Red Hat CVE, EUVD).
Successful exploitation causes a kernel crash, resulting in a denial of service (system unavailability). The impact is limited to availability — there is no confidentiality or integrity impact. An attacker with local access and low privileges who can connect a malicious or specially crafted USB hub device can trigger the crash, potentially affecting any system using USB Type-C docking stations, hubs, or DisplayPort Alt mode-capable devices (Feedly, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires local access and a low-privilege account, along with physical access to connect a malicious USB device, which significantly limits the attack surface. The EPSS score is approximately 0.032% (0.000320), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).
Patches have been merged into multiple Linux kernel stable branches. Fixed versions include: 5.4.257, 5.10.195, 5.15.132, 6.1.53, 6.4.16, 6.5.3, and 6.6. Organizations should update to a patched kernel version as the primary remediation. As a temporary workaround, restricting physical USB port access on sensitive systems can reduce exposure until patches are applied, since exploitation requires connecting a malicious USB device (Red Hat CVE, EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."