CVE-2026-46188

MEDIUM

octeon_ep_vf: add NULL check for napi_build_skb()

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: octeon_ep_vf: add NULL check for napi_build_skb() napi_build_skb() can return NULL on allocation failure. In __octep_vf_oq_process_rx(), the result is used directly without a NULL check in both the single-buffer and multi-fragment paths, leading to a NULL pointer dereference. Add NULL checks after both napi_build_skb() calls, properly advancing descriptors and consuming remaining fragments on failure.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 2.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (12)
Linux/Linux < 6.9
Linux/Linux 1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 - 60246cdd4c515ea7d920cddf48932efcb990773e
Linux/Linux 1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 - 6fef6640bbf360e254cc0174365ed30ce3a07572
Linux/Linux 1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 - b0f4711b426a06fb4c4be85c36b9f5588d5140d3
Linux/Linux 1cd3b407977c3ab1d2ddc26cb7113e7fb1509cd1 - dd66b42854705e4e4ee7f14d260f86c578bed3e3
Linux/Linux 6.12.88 - 6.12.*
Linux/Linux 6.18.30 - 6.18.*
Linux/Linux 6.9
Linux/Linux 7.0.7 - 7.0.*
Linux/Linux 7.1
... and 2 more
Published May 28, 2026
Tracked Since May 28, 2026