PT-2026-26045 · Linux+2 · Linux Kernel+2
CVE-2026-23242
·
Publicado
2026-01-01
·
Atualizado
2026-08-30
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw within the RDMA/siw component related to header processing. Specifically, a potential NULL pointer dereference can occur in the
siw tcp rx data() function if siw get hdr() returns -EINVAL before set rx fpdu context(), leading to qp->rx fpdu being NULL. The error path then attempts to dereference qp->rx fpdu->more ddp segs without a prior check, potentially causing a NULL pointer dereference. The issue is identified through KASAN reports indicating a null-ptr-deref within the specified memory range.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linuxmint
Linux Kernel
Ubuntu