Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.19.0-rc5_for_upstream_min_debug_2026_01_14_16_47, < 6.19.0-rc5_for_upstream_min_debug_2026_01_14_16_47
A null pointer dereference vulnerability has been identified in the Linux kernel's handling of IPsec resources for Mellanox devices when transitioning to switchdev mode. This issue occurs in versions through 6.19.0-rc5, and is caused by an improper cleanup of IPsec resources on devices that do not support IPsec, leading to a crash. The vulnerability can be reproduced by moving a Mellanox device to switchdev mode without IPsec support, which triggers a kernel null pointer dereference error.
The vulnerability causes a kernel null pointer dereference, leading to a crash.
To reproduce this vulnerability, move a Mellanox device to switchdev mode while the device is running a Linux kernel version through 6.19.0-rc5 and does not support IPsec. This will trigger a null pointer dereference in the kernel, causing a crash.
Users can upgrade to a patched version of the Linux kernel that includes the fix for this vulnerability. The patch is available in the Linux kernel stable tree.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.