CVE-2026-42801: Deference after null check in as_rrc
Published Sep 23, 2026
·Updated
NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (asrrc module) allows Pointer Manipulation.
This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.
Affected Software
2 affected components
ASR Crane
ASR Falcon
Event History
Sep 23, 2026
CVE Published
via MITRE·09:03 AM
Data Sourced
via MITRE·09:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access would an attacker need to exploit this issue?
The CVSS vector indicates network access is possible, exploitation has low attack complexity, and the attacker needs low privileges. No user interaction is required.
2
What security impact is indicated by the severity vector?
The vector indicates low impacts to confidentiality, integrity, and availability, with scope changed. The listed severity is high with a CVSS score of 7.4.
3
Which systems should be investigated first?
Investigate Linux deployments using ASR Crane or Falcon where the as_rrc module is present, particularly installations containing 3g.mod/lib/src/urrsir.c. The provided data does not identify affected or fixed versions.