CVE Database
/

CVE-2026-23242

Back to search

CVE-2026-23242

Published: Mar 18, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in header processing If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(), qp->rx_fpdu can be NULL. The error path in siw_tcp_rx_data() dereferences qp->rx_fpdu->more_ddp_segs without checking, which may lead to a NULL pointer deref. Only check more_ddp_segs when rx_fpdu is present. KASAN splat: [ 101.384271] KASAN: null-ptr-deref in range [0x00000000000000c0-0x00000000000000c7] [ 101.385869] RIP: 0010:siw_tcp_rx_data+0x13ad/0x1e50

VendorProductVersions

Linux

Linux

affected
8b6a361b8c482f22ac99c3273285ff16b23fba91 - < ab61841633d10e56a58c1493a262f0d02dba2f5e
affected
8b6a361b8c482f22ac99c3273285ff16b23fba91 - < 8564dcc12fbb372d984ab45768cae9335777b274
affected
8b6a361b8c482f22ac99c3273285ff16b23fba91 - < ab957056192d6bd068b3759cb2077d859cca01f0
affected
8b6a361b8c482f22ac99c3273285ff16b23fba91 - < ffba40b67663567481fa8a1ed5d2da36897c175d
affected
8b6a361b8c482f22ac99c3273285ff16b23fba91 - < 87b7a036d2c73d5bb3ae2d47dee23de465db3355

+3 more versions

Linux

Linux

affected
5.3
unaffected
0 - < 5.3
unaffected
5.10.252 - <= 5.10.*
unaffected
5.15.202 - <= 5.15.*
unaffected
6.1.165 - <= 6.1.*

+5 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now