PT-2026-5522 · Linux+3 · Linux Kernel+3

Published

2026-01-01

·

Updated

2026-05-26

·

CVE-2026-23019

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s networking subsystem related to Marvell Prestera devices. A failure in the devlink alloc() function to allocate memory can lead to a NULL pointer dereference within the prestera devlink alloc() function when it unconditionally calls devlink priv() on the returned pointer. This can cause a system crash. The issue arises because devlink alloc() may return NULL upon allocation failure, but the code does not check for this condition before attempting to access the returned pointer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-04097
CVE-2026-23019
ECHO-B830-9BC8-D435
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8243-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2

Affected Products

Linuxmint
Linux Kernel
Marvell Prestera
Ubuntu