SB2026011452 - NULL pointer dereference in Linux kernel target driver
Published: January 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-68782)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the target_cmd_init_cdb() function in drivers/target/target_core_transport.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0260ad551b0815eb788d47f32899fbcd65d6f128
- https://git.kernel.org/stable/c/0d36db68fdb8a3325386fd9523b67735f944e1f3
- https://git.kernel.org/stable/c/5053eab38a4c4543522d0c320c639c56a8b59908
- https://git.kernel.org/stable/c/8727663ded659aad55eef21e3864ebf5a4796a96
- https://git.kernel.org/stable/c/8edbb9e371af186b4cf40819dab65fafe109df4d