CVE-2026-23020: net: 3com: 3c59x: fix possible null dereference in vortex_probe1()
Published Jan 31, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
net: 3com: 3c59x: fix possible null dereference in vortexprobe1()
pdev can be null and freering: can be called in 1297 with a null pdev.
Affected Software
17 affected components
Linux Foundation Linux Kernel
Linux Linux kernel>=4.16.12<4.17
Linux Linux kernel>=4.17.1<5.10.248
Linux Linux kernel>=5.11<5.15.198
Linux Linux kernel>=5.16<6.1.161
Linux Linux kernel>=6.2<6.6.121
Linux Linux kernel>=6.7<6.12.66
Linux Linux kernel>=6.13<6.18.6
Linux Linux kernel=4.17
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3
Linux Linux kernel=6.19-rc4
Linux Linux kernel=6.19-rc5
Linux Linux kernel=6.19-rc6
Linux Linux kernel=6.19-rc7
Linux Linux kernel=6.19-rc8
Remediation
Event History
Jan 31, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
Description
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-23020?
CVE-2026-23020 is considered a moderate severity vulnerability due to the potential for null dereference leading to denial of service.
2
What does CVE-2026-23020 affect?
CVE-2026-23020 affects the 3Com 3c59x network driver in the Linux kernel.
3
How do I fix CVE-2026-23020?
To fix CVE-2026-23020, ensure that you update to the latest version of the Linux kernel that contains the patch for this vulnerability.
4
What type of vulnerability is CVE-2026-23020?
CVE-2026-23020 is a null dereference vulnerability that could cause a denial of service.
5
When was CVE-2026-23020 disclosed?
CVE-2026-23020 was disclosed as part of security updates for the Linux kernel addressing network driver issues.