CVE-2026-42800: Deference after null check in ims_client sip
Published Apr 30, 2026
·Updated
NULL pointer dereference vulnerability in ASR1903 in ASR LapwingLinux on Linux (imsclient modules) allows Pointer Manipulation.
This vulnerability is associated with program files sip/utils/src/sipuri.c.
Affected Software
5 affected components
Cisco ASR 1903 (Lapwing_Linux)
All of the following
Asrmicro Asr1901 Firmware<1.225.003
Asrmicro Asr1901
All of the following
Asrmicro Asr1903 Firmware<1.225.003
Asrmicro Asr1903
Event History
Apr 30, 2026
CVE Published
via MITRE·08:52 AM
Data Sourced
via MITRE·08:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-42800?
CVE-2026-42800 is classified as a medium severity vulnerability due to its potential to allow pointer manipulation.
2
How do I fix CVE-2026-42800?
To mitigate CVE-2026-42800, ensure that your Cisco ASR 1903 devices are updated with the latest security patches from Cisco.
3
What systems are affected by CVE-2026-42800?
CVE-2026-42800 specifically affects Cisco ASR 1903 devices running Lapwing_Linux.
4
What could happen if CVE-2026-42800 is exploited?
Exploitation of CVE-2026-42800 could lead to a denial of service condition due to a null pointer dereference.
5
When was CVE-2026-42800 disclosed?
CVE-2026-42800 was disclosed in 2026, highlighting a significant security risk in the affected systems.