Medium severity5.5NVD Advisory· Published Jan 31, 2026· Updated Jul 14, 2026
CVE-2026-23019
CVE-2026-23019
Description
In the Linux kernel, the following vulnerability has been resolved:
net: marvell: prestera: fix NULL dereference on devlink_alloc() failure
devlink_alloc() may return NULL on allocation failure, but prestera_devlink_alloc() unconditionally calls devlink_priv() on the returned pointer.
This leads to a NULL pointer dereference if devlink allocation fails. Add a check for a NULL devlink pointer and return NULL early to avoid the crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.10.1,<5.15.198
- cpe:2.3:o:linux:linux_kernel:5.10:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 5.10
Patches
Vulnerability mechanics
References
7- git.kernel.org/stable/c/325aea74be7e192b5c947c782da23b0d19a5fda2nvdPatch
- git.kernel.org/stable/c/326a4b7e61d01db3507f71c8bb5e85362f607064nvdPatch
- git.kernel.org/stable/c/3950054c9512add0cc79ab7e72b6d2f9f675e25bnvdPatch
- git.kernel.org/stable/c/8a4333b2818f0d853b43e139936c20659366e4a0nvdPatch
- git.kernel.org/stable/c/94e070cd50790317fba7787ae6006934b7edcb6fnvdPatch
- git.kernel.org/stable/c/a428e0da1248c353557970848994f35fd3f005e2nvdPatch
- cert-portal.siemens.com/productcert/html/ssa-019113.htmlnvd
News mentions
1- Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPCISA ICS Advisories