{"id":"DEBIAN-CVE-2023-54321","details":"In the Linux kernel, the following vulnerability has been resolved:  driver core: fix potential null-ptr-deref in device_add()  I got the following null-ptr-deref report while doing fault injection test:  BUG: kernel NULL pointer dereference, address: 0000000000000058 CPU: 2 PID: 278 Comm: 37-i2c-ds2482 Tainted: G    B   W        N 6.1.0-rc3+ RIP: 0010:klist_put+0x2d/0xd0 Call Trace:  \u003cTASK\u003e  klist_remove+0xf1/0x1c0  device_release_driver_internal+0x196/0x210  bus_remove_device+0x1bd/0x240  device_add+0xd3d/0x1100  w1_add_master_device+0x476/0x490 [wire]  ds2482_probe+0x303/0x3e0 [ds2482]  This is how it happened:  w1_alloc_dev()   // The dev-\u003edriver is set to w1_master_driver.   memcpy(&dev-\u003edev, device, sizeof(struct device));   device_add()     bus_add_device()     dpm_sysfs_add() // It fails, calls bus_remove_device.      // error path     bus_remove_device()       // The dev-\u003edriver is not null, but driver is not bound.       __device_release_driver()         klist_remove(&dev-\u003ep-\u003eknode_driver) \u003c-- It causes null-ptr-deref.      // normal path     bus_probe_device() // It's not called yet.       device_bind_driver()  If dev-\u003edriver is set, in the error path after calling bus_add_device() in device_add(), bus_remove_device() is called, then the device will be detached from driver. But device_bind_driver() is not called yet, so it causes null-ptr-deref while access the 'knode_driver'. To fix this, set dev-\u003edriver to null in the error path before calling bus_remove_device().","modified":"2026-09-15T09:02:53.495004844Z","published":"2025-12-30T13:16:21.410Z","upstream":["CVE-2023-54321"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-54321"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54321.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54321.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-54321.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}