CVE-2026-68291: idpf: fix max_vport related crash on allocation error during init

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

idpf: fix maxvport related crash on allocation error during init

Set adapter->maxvports only after successful allocation of vports, netdevs and vportconfig buffers. This fixes possible crashes on reset or rmmod, following failed allocation on init

[ 305.981402] idpf 0000:83:00.0: enabling device (0100 -> 0102) [ 305.994464] idpf 0000:83:00.0: Device HW Reset initiated [ 320.416872] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 320.416918] #PF: supervisor read access in kernel mode [ 320.416942] #PF: errorcode(0x0000) - not-present page [ 320.416963] PGD 2099657067 P4D 0 [ 320.416983] Oops: Oops: 0000 [#1] SMP NOPTI ... [ 320.417093] RIP: 0010:idpfremove+0x118/0x200 [idpf] [ 320.417130] Code: 8b bb 98 09 00 00 e8 17 0f 5b e5 48 8b bb e8 08 00 00 e8 0b 0f 5b e5 66 83 bb 28 06 00 00 00 48 8b bb 20 06 00 00 74 49 31 ed <48> 8b 04 ef 48 85 c0 74 2f 48 8b 78 20 e8 66 58 91 e5 48 8b 83 20 [ 320.417183] RSP: 0018:ff7322212903fdb8 EFLAGS: 00010246 [ 320.417205] RAX: 0000000000000000 RBX: ff4463de40300000 RCX: ff7322212903fd4c [ 320.417228] RDX: 0000000000000001 RSI: ffffffffa7f7d100 RDI: 0000000000000000 [ 320.417250] RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000 [ 320.417272] R10: 0000000000000001 R11: ff4463de3a638f58 R12: ff4463be89ac7000 [ 320.417294] R13: ff4463be89ac7198 R14: ff4463be94fc7198 R15: ffffffffc0f10f20 [ 320.417317] FS: 00007f963c0e6740(0000) GS:ff4463fdd65d8000(0000) knlGS:0000000000000000 [ 320.417342] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 320.417362] CR2: 0000000000000000 CR3: 00000020ba674002 CR4: 0000000000773ef0 [ 320.417385] PKRU: 55555554 [ 320.417398] Call Trace: [ 320.417412] <TASK> [ 320.417429] pcideviceremove+0x42/0xb0 [ 320.417459] devicereleasedriverinternal+0x1a9/0x210 [ 320.417492] driverdetach+0x4b/0x90 [ 320.417516] busremovedriver+0x70/0x100 [ 320.417539] pciunregisterdriver+0x2e/0xb0 [ 320.417564] dosysdeletemodule.constprop.0+0x190/0x2f0 [ 320.417592] ? kmemcachefree+0x31e/0x550 [ 320.417619] ? lockdephardirqsonprepare+0xde/0x190 [ 320.417644] ? dosyscall64+0x38/0x6b0 [ 320.417665] dosyscall64+0xc8/0x6b0 [ 320.417683] ? clearbhbloop+0x30/0x80 [ 320.417706] entrySYSCALL64afterhwframe+0x76/0x7e [ 320.417727] RIP: 0033:0x7f963bb30beb

Affected Software

1 affected component
Linux Kernel

Event History

Aug 10, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68291?

CVE-2026-68291 has a risk score of 22, indicating a severe impact on system stability.

2

What type of vulnerability is CVE-2026-68291?

CVE-2026-68291 is classified as a Null Pointer Dereference vulnerability.

3

How do I fix CVE-2026-68291?

Fix CVE-2026-68291 by applying the latest updates for the Linux kernel that address this allocation error.

4

What systems are affected by CVE-2026-68291?

CVE-2026-68291 affects systems running vulnerable versions of the Linux kernel with the idpf driver.

5

What are the consequences of CVE-2026-68291?

CVE-2026-68291 can lead to crashes during the initialization process, particularly on reset or module removal.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203