NULL pointer dereference in Linux kernel - CVE-2026-43413

 

NULL pointer dereference in Linux kernel - CVE-2026-43413

Published: May 8, 2026


Vulnerability identifier: #VU130765
CSH Severity: Low
CVSS v4 BT: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2026-43413
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the hisi_sas user_scan() handling path when processing a user-initiated scan request. A local user can write a crafted scan request via sysfs to trigger a kernel crash and cause a denial of service.

The issue is triggered because the driver supports only one channel, but scanning proceeds to an additional channel value.


Affected software

Linux kernel
Ubuntu
openEuler
bpftool
kernel
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)

How to mitigate CVE-2026-43413

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
bpftool - update to 6.6.0-145.1.15.153
kernel - update to 6.6.0-145.1.15.153
python3-perf-debuginfo - update to 6.6.0-145.1.15.153
python3-perf - update to 6.6.0-145.1.15.153
perf-debuginfo - update to 6.6.0-145.1.15.153
perf - update to 6.6.0-145.1.15.153
kernel-tools-devel - update to 6.6.0-145.1.15.153
kernel-tools-debuginfo - update to 6.6.0-145.1.15.153
kernel-tools - update to 6.6.0-145.1.15.153
kernel-source - update to 6.6.0-145.1.15.153
kernel-headers - update to 6.6.0-145.1.15.153
kernel-devel - update to 6.6.0-145.1.15.153
kernel-debugsource - update to 6.6.0-145.1.15.153
kernel-debuginfo - update to 6.6.0-145.1.15.153
bpftool-debuginfo - update to 6.6.0-145.1.15.153
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - update to 6.8.0-1061.64+1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1

External References

Related Security Bulletins