CVE 7.5 HIGH

RDMA/siw: Fix potential NULL pointer dereference in header processing_CVE-2026-23242

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Fix potential NULL pointer dereference in header processing

If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(),
qp->rx_fpdu can be NULL. The error path in siw_tcp_rx_data()
dereferences qp->rx_fpdu->more_ddp_segs without checking, which
may lead to a NULL pointer deref. Only check more_ddp_segs when
rx_fpdu is present.

KASAN splat:
[ 101.384271] KASAN: null-ptr-deref in range [0x00000000000000c0-0x00000000000000c7]
[ 101.385869] RIP: 0010:siw_tcp_rx_data+0x13ad/0x1e50

Basic Information

ID CVE-2026-23242
Source Linux
Published Mar 18, 2026 at 10:05
Modified Apr 2, 2026 at 14:43

Affected Product

Vendor Linux
Product Linux
Version 8b6a361b8c482f22ac99c3273285ff16b23fba91
Affected Versions Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91
Linux Linux 5.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.