PT-2026-6154 · Linux+2 · Linux Kernel+2
Published
2026-01-01
·
Updated
2026-05-22
·
CVE-2026-23084
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the be2net driver within the Linux kernel where a NULL pointer dereference can occur in the
be cmd get mac from list() function. This happens when the pmac id valid parameter is set to false and the pmac id parameter is NULL, potentially leading to a system crash or unexpected behavior. The issue arises from passing a NULL address to the function when it expects a valid memory location to store the PMAC ID retrieved from the network card's firmware. The fix involves ensuring a valid memory address, such as a stub variable, is always provided to the function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu