{"id":"DEBIAN-CVE-2023-54198","details":"In the Linux kernel, the following vulnerability has been resolved:  tty: fix out-of-bounds access in tty_driver_lookup_tty()  When specifying an invalid console= device like console=tty3270, tty_driver_lookup_tty() returns the tty struct without checking whether index is a valid number.  To reproduce:  qemu-system-x86_64 -enable-kvm -nographic -serial mon:stdio \\ -kernel ../linux-build-x86/arch/x86/boot/bzImage \\ -append \"console=ttyS0 console=tty3270\"  This crashes with:  [    0.770599] BUG: kernel NULL pointer dereference, address: 00000000000000ef [    0.771265] #PF: supervisor read access in kernel mode [    0.771773] #PF: error_code(0x0000) - not-present page [    0.772609] Oops: 0000 [#1] PREEMPT SMP PTI [    0.774878] RIP: 0010:tty_open+0x268/0x6f0 [    0.784013]  chrdev_open+0xbd/0x230 [    0.784444]  ? cdev_device_add+0x80/0x80 [    0.784920]  do_dentry_open+0x1e0/0x410 [    0.785389]  path_openat+0xca9/0x1050 [    0.785813]  do_filp_open+0xaa/0x150 [    0.786240]  file_open_name+0x133/0x1b0 [    0.786746]  filp_open+0x27/0x50 [    0.787244]  console_on_rootfs+0x14/0x4d [    0.787800]  kernel_init_freeable+0x1e4/0x20d [    0.788383]  ? rest_init+0xc0/0xc0 [    0.788881]  kernel_init+0x11/0x120 [    0.789356]  ret_from_fork+0x22/0x30","modified":"2026-09-15T09:02:53.167140741Z","published":"2025-12-30T13:16:07.877Z","upstream":["CVE-2023-54198"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54198"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54198.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54198.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54198.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}