Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: csiostor: Fix dereference of null pointer rn

The error exit path when rn is NULL ends up deferencing the null pointer rn
via the use of the macro CSIO_INC_STATS. Fix this by adding a new error
return path label after the use of the macro to avoid the deference.
Published: 2026-05-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A NULL pointer dereference occurs in the Linux kernel’s csiostor SCSI driver: when the variable rn is null, the CSIO_INC_STATS macro attempts to access it, causing a kernel fault. The fault results in a kernel panic, which brings the system to a halt. This flaw is a classic NULL pointer dereference (CWE‑476).

Affected Systems

All Linux kernel releases that include the legacy csiostor module and have not yet incorporated the patch that adds the error return path for rn. The vulnerability affects any system that uses SCSI devices, as the csiostor code is part of the core kernel modules for SCSI storage.

Risk and Exploitability

The CVSS score is not available in this dataset, and no EPSS value is provided; however the affected component is a critical kernel module. The likely attack vector is inferred to be local or intermediate, as malicious SCSI commands can be issued from user space or by a remote client capable of delivering SCSI commands (e.g., over a networked storage interface). The KEV catalog does not list this vulnerability. Given the severity of a kernel panic and the ability of an attacker to trigger it through SCSI commands, exploitation is plausible with moderate skill and would result in complete denial of service.

Generated by OpenCVE AI on May 27, 2026 at 16:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that contains the fix for the csiostor NULL pointer dereference.
  • If an immediate kernel upgrade is not possible, disable or remove SCSI adapters that are not required for production traffic to prevent the fault from being triggered.
  • Rebuild the csiostor module to incorporate the updated error handling and ensure the module loads correctly.

Generated by OpenCVE AI on May 27, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 27 May 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: csiostor: Fix dereference of null pointer rn The error exit path when rn is NULL ends up deferencing the null pointer rn via the use of the macro CSIO_INC_STATS. Fix this by adding a new error return path label after the use of the macro to avoid the deference.
Title scsi: csiostor: Fix dereference of null pointer rn
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-27T12:15:35.967Z

Reserved: 2026-05-13T15:03:33.079Z

Link: CVE-2026-45857

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-27T14:16:57.793

Modified: 2026-05-27T14:48:31.480

Link: CVE-2026-45857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-27T17:00:17Z

Weaknesses