IT

Tracker / CVE-2026-23285

CVE-2026-23285

Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: drbd: fix null-pointer dereference on local read error In drbd_request_endio(), READ_COMPLETED_WITH_ERROR is passed to __req_mod() with a NULL peer_device: __req_mod(req, what, NULL, &m); The READ_COMPLETED_WITH_ERROR handler then unconditionally passes this NULL peer_device to drbd_set_out_of_sync(), which dereferences it, causing a null-pointer dereference. Fix this by obtaining the peer_device via first_peer_device(device), matching how drbd_req_destroy() handles the same situation.

Affected products and versions

linux linux_kernel
linux linux_kernel · 6.13 → 6.18.17
linux linux_kernel · 6.19 → 6.19.7
linux linux_kernel · 6.4 → 6.6.130
linux linux_kernel · 6.7 → 6.12.77

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References