CVE-2026-23328

MEDIUM

accel/amdxdna: Fix NULL pointer dereference of mgmt_chann

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix NULL pointer dereference of mgmt_chann mgmt_chann may be set to NULL if the firmware returns an unexpected error in aie2_send_mgmt_msg_wait(). This can later lead to a NULL pointer dereference in aie2_hw_stop(). Fix this by introducing a dedicated helper to destroy mgmt_chann and by adding proper NULL checks before accessing it.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 4.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (11)
linux/Kernel 6.14.0 - 6.19.7linux
Linux/Linux < 6.14
Linux/Linux 6.14
Linux/Linux 6.19.7 - 6.19.*
Linux/Linux 7.0
Linux/Linux 7.0-rc3
Linux/Linux b87f920b934426a24d54613f12ed67c03ae05024 - 032ca7a9059c4ba6c329e0f1b442dab54dd9c3e5
Linux/Linux b87f920b934426a24d54613f12ed67c03ae05024 - 6270ee26e1edd862ea17e3eba148ca8fb2c99dc9
linux/linux_kernel 6.14
linux/linux_kernel 7.0 rc1 (7 CPE variants)
... and 1 more
Published Mar 25, 2026
Tracked Since Mar 25, 2026