Security Advisory

CVE-2023-54240

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-30 12:11:29
Last updated 2026-05-11 19:58:09
Assigner Linux
CVSS score not scored
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix possible NULL pointer dereference in mtk_hwlro_get_fdir_all() rule_locs is allocated in ethtool_get_rxnfc and the size is determined by rule_cnt from user space. So rule_cnt needs to be check before using rule_locs to avoid NULL pointer dereference.