cbcvebase.
CVE-2026-23084
published 2026-02-04

CVE-2026-23084: In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list When the parameter…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list When the parameter pmac_id_valid argument of be_cmd_get_mac_from_list() is set to false, the driver may request the PMAC_ID from the firmware of the network card, and this function will store that PMAC_ID at the provided address pmac_id. This is the contract of this function. However, there is a location within the driver where both pmac_id_valid == false and pmac_id == NULL are being passed. This could result in dereferencing a NULL pointer. To resolve this issue, it is necessary to pass the address of a stub variable to the function.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 95046b927a54f461766f83a212c6a93bc5fd2e67 < 4cba480c9b9a3861a515262225cb53a1f59783444cba480c9b9a3861a515262225cb53a1f5978344
linuxlinux>= 95046b927a54f461766f83a212c6a93bc5fd2e67 < 92c6dc181a18e6e0ddb872ed35cb48a9274829e492c6dc181a18e6e0ddb872ed35cb48a9274829e4
linuxlinux>= 95046b927a54f461766f83a212c6a93bc5fd2e67 < 6c3e00888dbec887125a08b51a705b9b163fcdd16c3e00888dbec887125a08b51a705b9b163fcdd1
linuxlinux>= 95046b927a54f461766f83a212c6a93bc5fd2e67 < e206fb415db36bad52bb90c08d46ce71ffbe8a80e206fb415db36bad52bb90c08d46ce71ffbe8a80
linuxlinux>= 95046b927a54f461766f83a212c6a93bc5fd2e67 < 47ffb4dcffe336f4a7bd0f3284be7aadc648469847ffb4dcffe336f4a7bd0f3284be7aadc6484698
linuxlinux>= 95046b927a54f461766f83a212c6a93bc5fd2e67 < 31410a01a86bcb98c798d01061abf1f789c4f75a31410a01a86bcb98c798d01061abf1f789c4f75a
linuxlinux>= 95046b927a54f461766f83a212c6a93bc5fd2e67 < 8215794403d264739cc676668087512950b2ff318215794403d264739cc676668087512950b2ff31
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 3.12 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.