CVE-2023-28328 affects the Linux kernel's AZ6027 USB DVB media-driver I2C transfer routine, az6027_i2c_xfer(). A local low-privileged user can submit a crafted I2C message—such as address 0x99 with zero length and a NULL buffer—causing the driver to dereference msg[i].buf[0] and crash the kernel. The defect was found through kernel fuzzing, which reproduced a KASAN-detected general-protection fault through the I2C_RDWR ioctl path.
The upstream fix validates that the I2C message length is at least one before accessing its buffer and returns -EOPNOTSUPP for invalid requests. Red Hat rated the issue Moderate with CVSS 3.1 score 5.5, released fixes for affected RHEL 8 kernel streams, and stated that RHEL 9 is unaffected. Until patched, administrators can reduce exposure by blacklisting the dvb_usb_az6027 kernel module where the associated hardware is not required.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released fixes for affected Red Hat Enterprise Linux 8 kernel and kernel-rt streams through RHSA-2023:7077 and RHSA-2023:6901. The flaw allows a local low-privileged user to crash the system through a NULL pointer dereference in the az6027 driver.
Baisong Zhong submitted a patch to reject zero-length I2C messages before az6027_i2c_xfer accesses msg[i].buf[0]. The proposed fix returns -EOPNOTSUPP for the invalid message condition reported by Wei Chen.
Wei Chen reported a reproducible general-protection fault and KASAN-detected null-pointer dereference in the Linux AZ6027 USB DVB driver's az6027_i2c_xfer function. The issue was reachable through the I2C_RDWR ioctl path and persisted in upstream Linux v6.1-rc5.
Red Hat released RHSA-2024:0724 to fix CVE-2023-28328 for Red Hat Enterprise Linux 8.6 Extended Update Support and Red Hat Virtualization 4 for RHEL 8.
Red Hat released RHSA-2024:0575 to address CVE-2023-28328 for Red Hat Enterprise Linux 8.8 Extended Update Support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.