Junglewise Threat Intelligence

CVE-2026-53338: Linux kernel NULL pointer dereference in Airoha Ethernet driver

CVE-2026-53338 · Severity: info · Published 2026-07-01

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Airoha Ethernet driver. Under specific conditions where system memory is misconfigured, the system may experience a kernel crash (NULL pointer dereference). This could lead to a denial-of-service, impacting the availability of the affected device.

Technical details

A NULL pointer dereference vulnerability exists in the Linux kernel within the Airoha Ethernet driver (airoha_eth.c). The function airoha_qdma_init_hfwd_queues() calls of_reserved_mem_lookup() but fails to validate the return value. If a 'memory-region' phandle is missing or misconfigured in the Device Tree Source (DTS), the function returns NULL, which is subsequently dereferenced when accessing rmem->base. This results in a kernel panic. The issue has been resolved by adding a NULL check that returns -ENODEV upon failure.

Affected products

  • Linux Linux 6.16, 6.18.36, 7.0.13

Timeline

  • 2026-06-04: other: Patch authored
  • 2026-07-01: disclosed: CVE published

References