SB20260812209 - NULL pointer dereference in Linux kernel net wan driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-68327)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in wanxl_reset in the wanxl PCI device removal path when handling early probe failures before BAR mapping. A local user can trigger device initialization failure conditions to cause a denial of service.
The issue occurs on an error path where the PLX MMIO BAR has not yet been mapped, leaving card->plx NULL when cleanup invokes the reset routine.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2fe22d58b3797d741570f9873b26653fd511576c
- https://git.kernel.org/stable/c/59cbe6cfa0fa23c192351cc284e30707309f6741
- https://git.kernel.org/stable/c/91957b89da995607cb654b1f9a3c126ddbaee10f
- https://git.kernel.org/stable/c/b9e2ff70e96acf83693b27987e0390bad9f83efa
- https://git.kernel.org/stable/c/f4834132773f15ffb255127499c8443947fa7d0f