PT-2026-98125 · Linux · Linux Kernel

CVE-2026-97506

·

Published

2026-09-24

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A null-pointer dereference can occur in the crypto: ixp4xx component. The chainup buffers() function, which creates a linked list of buffer descriptors for a scatterlist, fails to handle allocation errors from dma pool alloc() correctly. When an allocation fails, the buf variable is set to NULL but is subsequently dereferenced, leading to a system crash. Additionally, if a failure occurs after some descriptors have been allocated and DMA-mapped, the partially constructed chain is not properly released. The ablk perform() function also fails to preserve hook pointers before checking for failure, which prevents the correct freeing of partially built chains.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97506

Affected Products

Linux Kernel