SB20260812402 - NULL pointer dereference in Linux kernel iucv
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-68141)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in afiucv_hs_callback_syn() when handling connection requests that enter the connection-refused path after child socket allocation fails. A local user can trigger this condition to cause a denial of service.
The issue occurs because the code calls iucv_sock_kill() with a NULL child socket pointer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0e857185591fe79934427c9c0c1c31dc776be134
- https://git.kernel.org/stable/c/33736ff5e7c97d3348ce812e8bd2e125d840743c
- https://git.kernel.org/stable/c/46453b16f38ec7147351f7447e2aec6ea330f7b3
- https://git.kernel.org/stable/c/47a5116e56a6b6fe1e909f244e39cd0fc26ceee4
- https://git.kernel.org/stable/c/8bb111f87ded6acb9837ec9b45d6f02cda94c51f