{"id":"CVE-2026-81005","title":"kernel: ipmi: si: Fix NULL pointer dereference after failed registration (CVE-2026-81005)","summary":"A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) subsystem. During the registration of an IPMI message handler, if the Baseboard Management Controller (BMC) device information cannot be fetched, a NUL…","severity":"medium","cvss":4.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-476","vendor":"Red Hat","product":"Linux","affected":["Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < 75ecc80ef0614a9f8441ab476fb748d3e919bea8","Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < b11a1e545ad7a2f8f9ba7276b4ae9429c3399456","Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < f390b0e781ca689515b659f94ef05f01497ed833","Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < d377bf743f29b41729a084a633874ef9c1a13c6a","Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < d4be659a3e56f4eb16039ab8a1162efea086a714","Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < 53af3a8bae0a93c1342e1b5519812203332aca8e","Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < 8ada17dd4c4ffd6b94621e735d77eda196ce118f","Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 < 6d920a75df9a83ab096b3cde7a643b656e4fdfeb","Linux 288bd736c8a027040fc261c86a87b65e7bc3f6fa","Linux >= 4.18.10 < 4.19","Linux 4.19"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:45:12+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81005.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81005.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81005"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532315"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81005"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81005"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81005.mbox"},{"url":"https://git.kernel.org/stable/c/75ecc80ef0614a9f8441ab476fb748d3e919bea8"},{"url":"https://git.kernel.org/stable/c/b11a1e545ad7a2f8f9ba7276b4ae9429c3399456"},{"url":"https://git.kernel.org/stable/c/f390b0e781ca689515b659f94ef05f01497ed833"},{"url":"https://git.kernel.org/stable/c/d377bf743f29b41729a084a633874ef9c1a13c6a"},{"url":"https://git.kernel.org/stable/c/d4be659a3e56f4eb16039ab8a1162efea086a714"},{"url":"https://git.kernel.org/stable/c/53af3a8bae0a93c1342e1b5519812203332aca8e"},{"url":"https://git.kernel.org/stable/c/8ada17dd4c4ffd6b94621e735d77eda196ce118f"},{"url":"https://git.kernel.org/stable/c/6d920a75df9a83ab096b3cde7a643b656e4fdfeb"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00176,"epssPercentile":0.07418,"ingestedAt":"2026-09-14T15:23:07.454Z","slug":"CVE-2026-81005","body":"## Overview\n\nA flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) subsystem. During the registration of an IPMI message handler, if the Baseboard Management Controller (BMC) device information cannot be fetched, a NULL pointer dereference can occur. This can allow a local attacker to trigger a kernel crash, resulting in a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81005.json)\n\n**kernel: ipmi: si: Fix NULL pointer dereference after failed registration** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":22.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204140,"id":"CVE-2026-81005","ts":1789490232088,"field":"cvss","old":null,"new":"4.1"},{"seq":204139,"id":"CVE-2026-81005","ts":1789490232088,"field":"severity","old":"none","new":"medium"}]}