Medium severity5.5NVD Advisory· Published Jun 26, 2026· Updated Jul 8, 2026
CVE-2026-53299
CVE-2026-53299
Description
In the Linux kernel, the following vulnerability has been resolved:
net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()
If queue entry list allocation fails in airoha_qdma_init_tx_queue routine, airoha_qdma_cleanup_tx_queue() will trigger a NULL pointer dereference accessing the queue entry array. The issue is due to the early ndesc initialization in airoha_qdma_init_tx_queue(). Fix the issue moving ndesc initialization at end of airoha_qdma_init_tx routine.
Affected products
3Patches
Vulnerability mechanics
References
3News mentions
1- Linux Kernel: 25 Vulnerabilities Affecting Networking, Graphics, and Memory Management Disclosed TogetherVypr Intelligence · Jun 27, 2026