
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22982 is a NULL pointer dereference vulnerability in the Linux kernel's MSCC Ocelot network driver that allows a local low-privileged attacker to crash the kernel, resulting in a denial of service. The flaw resides in the ocelot_set_aggr_pgids() function within the ocelot_vsc7514.c frontend, which fails to validate port pointers before accessing them when a network interface is added under a Link Aggregation Group (LAG). Affected Linux kernel versions span 5.12 through 6.19-rc4 across multiple stable branches. It was published on January 23, 2026, with CVSS v3.1 base score of 5.5 (Medium) (Feedly, Red Hat Bugzilla).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference). The ocelot_vsc7514.c frontend leaves unused ports as NULL pointers, and the ocelot_set_aggr_pgids() function does not check whether a port pointer is valid before dereferencing it during LAG interface configuration. This mirrors a previously fixed issue in the lan966x driver (commit 15faa1f67ab4). The felix_vsc9959.c frontend is unaffected because it uses the DSA framework, which registers all ports and avoids NULL entries. Exploitation requires local access with low privileges and no user interaction, making it a straightforward local denial-of-service trigger for any user with network interface configuration rights (Feedly).
Successful exploitation causes a kernel crash (panic), resulting in a complete denial of service for the affected system. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Systems running the ocelot_vsc7514.c frontend (e.g., embedded networking hardware using the VSC7514 switch chip) are at risk of being rendered unavailable until rebooted (Feedly).
Apply kernel updates to the following patched versions: 5.15.198 or later (for 5.12–5.15 branch), 6.1.161 or later (for 5.16–6.1 branch), 6.6.121 or later (for 6.2–6.6 branch), 6.12.66 or later (for 6.7–6.12 branch), or 6.18.6 or later (for 6.13+ branch). Patch commits are available via the stable kernel tree on git.kernel.org. As a temporary workaround for systems that cannot be patched immediately, restrict network interface configuration privileges to trusted administrators only to reduce exposure (Feedly, Red Hat Bugzilla).
The vulnerability has been tracked by Red Hat (BZ#2432393), Microsoft (CBL-Mariner kernel), SUSE, and Ubuntu, all of which have issued kernel update advisories. Downstream distributions including Ubuntu (USN-8278-1, USN-8289-1, USN-8296-1, USN-8278-2, USN-8289-2, USN-8296-2) and SUSE (SUSE-2026-0962-1) have published security notices. No notable independent researcher commentary or significant social media discussion has been identified beyond routine CVE tracking (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."