Description
NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation.

This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.
Published: 2026-09-23
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability is a null pointer dereference in the as_rrc module of ASR Crane and Falcon Linux devices, located in the file urrsir.c. The flaw can be triggered through pointer manipulation, potentially causing the process that uses the module to crash or behave unpredictably. The weakness is identified as CWE‑476 and may result in denial of service or instability of the affected service, though no explicit mention of code execution is provided in the CVE description.

Affected Systems

The vulnerability affects ASR Crane and Falcon Linux devices. No specific product versions are identified, so all releases may be susceptible until a vendor‑issued fix is applied.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. The EPSS score is below 1%, suggesting low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog, implying no widely known exploits. Based on the description, the likely attack requires an attacker to influence the as_rrc module or provide crafted input with sufficient privileges, pointing to a local or privileged attacker scenario. Prompt remediation is advised to mitigate potential denial of service.

Generated by OpenCVE AI on September 23, 2026 at 14:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official security patch or update firmware for ASR Crane and Falcon when released.
  • If a patch is not yet available, restrict access to the affected device and disable or sandbox the as_rrc module if it is not required for business operations.
  • Ensure that all input to the as_rrc module is validated and that null checks are enforced before dereferencing pointers.

Generated by OpenCVE AI on September 23, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Asr
Asr crane,falcon
Vendors & Products Asr
Asr crane,falcon

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.
Title Deference after null check in as_rrc
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Asr Crane,falcon
cve-icon MITRE

Status: PUBLISHED

Assigner: ASR

Published:

Updated: 2026-09-23T15:25:17.517Z

Reserved: 2026-04-30T07:55:02.475Z

Link: CVE-2026-42801

cve-icon Vulnrichment

Updated: 2026-09-23T15:25:13.747Z

cve-icon NVD

Status : Received

Published: 2026-09-23T09:17:08.727

Modified: 2026-09-23T16:16:43.290

Link: CVE-2026-42801

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:36:55Z

Weaknesses