CVE-2026-23242

Source
https://cve.org/CVERecord?id=CVE-2026-23242
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23242.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23242
Downstream
Published
2026-03-18T10:05:05.108Z
Modified
2026-04-14T03:47:17.917715Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
RDMA/siw: Fix potential NULL pointer dereference in header processing
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/siw: Fix potential NULL pointer dereference in header processing

If siwgethdr() returns -EINVAL before setrxfpducontext(), qp->rxfpdu can be NULL. The error path in siwtcprxdata() dereferences qp->rxfpdu->moreddpsegs without checking, which may lead to a NULL pointer deref. Only check moreddpsegs when rx_fpdu is present.

KASAN splat: [ 101.384271] KASAN: null-ptr-deref in range [0x00000000000000c0-0x00000000000000c7] [ 101.385869] RIP: 0010:siwtcprx_data+0x13ad/0x1e50

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23242.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b6a361b8c482f22ac99c3273285ff16b23fba91
Fixed
ab61841633d10e56a58c1493a262f0d02dba2f5e
Fixed
8564dcc12fbb372d984ab45768cae9335777b274
Fixed
ab957056192d6bd068b3759cb2077d859cca01f0
Fixed
ffba40b67663567481fa8a1ed5d2da36897c175d
Fixed
87b7a036d2c73d5bb3ae2d47dee23de465db3355
Fixed
714c99e1dc8f85f446e05be02ba83972e981a817
Fixed
ce025f7f5d070596194315eb2e4e89d568b8a755
Fixed
14ab3da122bd18920ad57428f6cf4fade8385142

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23242.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.3.0
Fixed
5.10.252
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.202
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.165
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.128
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.75
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.14
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23242.json"