CVE-2026-23242

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2026
Last modified:
18/03/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> RDMA/siw: Fix potential NULL pointer dereference in header processing<br /> <br /> If siw_get_hdr() returns -EINVAL before set_rx_fpdu_context(),<br /> qp-&gt;rx_fpdu can be NULL. The error path in siw_tcp_rx_data()<br /> dereferences qp-&gt;rx_fpdu-&gt;more_ddp_segs without checking, which<br /> may lead to a NULL pointer deref. Only check more_ddp_segs when<br /> rx_fpdu is present.<br /> <br /> KASAN splat:<br /> [ 101.384271] KASAN: null-ptr-deref in range [0x00000000000000c0-0x00000000000000c7]<br /> [ 101.385869] RIP: 0010:siw_tcp_rx_data+0x13ad/0x1e50

Impact