SB20260507274 - NULL pointer dereference in Linux kernel intel ixgbevf driver
Published: May 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-43094)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the ixgbevf Hyper-V MAC operations table when probing the device on Hyper-V virtual machines. A local user can trigger device initialization to cause a denial of service.
The issue occurs because the negotiate_features callback is missing from the Hyper-V-specific operations table.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1455ff8809843e6e83f1f5b5c0bcc2224c99a3cb
- https://git.kernel.org/stable/c/2270ebab53128fb73c4a70a292be09094074737f
- https://git.kernel.org/stable/c/4821d563cd7f251ae728be1a6d04af82a294a5b9
- https://git.kernel.org/stable/c/4db7b61ec1d1b2b67c0881b62fc4f9583bc21484
- https://git.kernel.org/stable/c/d8a747057a17ffc79e31df1abb11d05e1669d8e5