CVE-2023-54299
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2023-54299 is a NULL pointer dereference vulnerability in the Linux kernel's USB Type-C Alt Mode bus driver (typec_altmode_attention). It affects Linux kernel versions from commit 8a37d87d72f0 up to multiple stable branch fix points, spanning kernel versions 4.19 through pre-6.6. The vulnerability was published on December 30, 2025, and has a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).

Technical details

The root cause is a missing NULL pointer check (CWE-476) in the typec_altmode_attention() function within the Linux kernel's USB Type-C bus driver (drivers/usb/typec/bus.c). When a USB hub negotiates DisplayPort Alt mode with a connected device and subsequently performs a data role swap, the device unregisters all Alt modes. However, the hub continues to send Attention messages; typec_altmode_attention does not verify whether the Alt Mode partner still exists before dereferencing typec_altmode and typec_altmode_ops structures, resulting in a NULL pointer dereference. The fix adds a partner existence check before forwarding the Attention message to the Alt Mode driver (Red Hat CVE, EUVD).

Impact

Successful exploitation causes a kernel crash, resulting in a denial of service (system unavailability). The impact is limited to availability — there is no confidentiality or integrity impact. An attacker with local access and low privileges who can connect a malicious or specially crafted USB hub device can trigger the crash, potentially affecting any system using USB Type-C docking stations, hubs, or DisplayPort Alt mode-capable devices (Feedly, Red Hat CVE).

Mitigation and workarounds

Patches have been merged into multiple Linux kernel stable branches. Fixed versions include: 5.4.257, 5.10.195, 5.15.132, 6.1.53, 6.4.16, 6.5.3, and 6.6. Organizations should update to a patched kernel version as the primary remediation. As a temporary workaround, restricting physical USB port access on sensitive systems can reduce exposure until patches are applied, since exploitation requires connecting a malicious USB device (Red Hat CVE, EUVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management