SB2026040699 - NULL pointer dereference in Linux kernel marvell mvpp2 driver
Published: April 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-23438)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in mvpp2_bm_switch_buffers() when switching between per-cpu and shared buffer pool modes. A local user can trigger a buffer mode switch, such as by changing the MTU across the jumbo frame threshold, to cause a denial of service.
The issue occurs when the CM3 SRAM resource is not present in the device tree, leaving priv->cm3_base NULL while flow control updates are still attempted.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/7bd20f4b3ef3044dc55acd5b8ef748a70d29d03f
- https://git.kernel.org/stable/c/7df2b50cae1a76cbb90b294f3edb61e3e10bf2e9
- https://git.kernel.org/stable/c/8a63baadf08453f66eb582fdb6dd234f72024723
- https://git.kernel.org/stable/c/8baced53a35fc9710f80d6ca016a2c418dc3231f
- https://git.kernel.org/stable/c/da089f74a993f846685067b14158cb41b879ff29
- https://git.kernel.org/stable/c/ff0c54f088f7ab91dbbf47cf8244460f99122750