---
id: CVE-2026-81005
title: >-
  kernel: ipmi: si: Fix NULL pointer dereference after failed registration
  (CVE-2026-81005)
summary: >-
  A flaw was found in the Linux kernel's Intelligent Platform Management
  Interface (IPMI) subsystem. During the registration of an IPMI message
  handler, if the Baseboard Management Controller (BMC) device information
  cannot be fetched, a NUL…
severity: medium
cvss: 4.1
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-476
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    75ecc80ef0614a9f8441ab476fb748d3e919bea8
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    b11a1e545ad7a2f8f9ba7276b4ae9429c3399456
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    f390b0e781ca689515b659f94ef05f01497ed833
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    d377bf743f29b41729a084a633874ef9c1a13c6a
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    d4be659a3e56f4eb16039ab8a1162efea086a714
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    53af3a8bae0a93c1342e1b5519812203332aca8e
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    8ada17dd4c4ffd6b94621e735d77eda196ce118f
  - >-
    Linux >= 2512e40e48d21d8bac09f7e91d2c3ceb2d3b50b2 <
    6d920a75df9a83ab096b3cde7a643b656e4fdfeb
  - Linux 288bd736c8a027040fc261c86a87b65e7bc3f6fa
  - Linux >= 4.18.10 < 4.19
  - Linux 4.19
published: '2026-09-11'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:45:12+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81005.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81005.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-81005'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532315'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-81005'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81005'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-81005.mbox
  - url: 'https://git.kernel.org/stable/c/75ecc80ef0614a9f8441ab476fb748d3e919bea8'
  - url: 'https://git.kernel.org/stable/c/b11a1e545ad7a2f8f9ba7276b4ae9429c3399456'
  - url: 'https://git.kernel.org/stable/c/f390b0e781ca689515b659f94ef05f01497ed833'
  - url: 'https://git.kernel.org/stable/c/d377bf743f29b41729a084a633874ef9c1a13c6a'
  - url: 'https://git.kernel.org/stable/c/d4be659a3e56f4eb16039ab8a1162efea086a714'
  - url: 'https://git.kernel.org/stable/c/53af3a8bae0a93c1342e1b5519812203332aca8e'
  - url: 'https://git.kernel.org/stable/c/8ada17dd4c4ffd6b94621e735d77eda196ce118f'
  - url: 'https://git.kernel.org/stable/c/6d920a75df9a83ab096b3cde7a643b656e4fdfeb'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00177
epssPercentile: 0.06448
ingestedAt: '2026-09-14T15:23:07.454Z'
---

## Overview

A flaw was found in the Linux kernel's Intelligent Platform Management Interface (IPMI) subsystem. During the registration of an IPMI message handler, if the Baseboard Management Controller (BMC) device information cannot be fetched, a NULL pointer dereference can occur. This can allow a local attacker to trigger a kernel crash, resulting in a denial of service.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81005.json)

**kernel: ipmi: si: Fix NULL pointer dereference after failed registration** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
