Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-30656

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.

A flaw was found in fio (Flexible I/O Tester). A local user could exploit this vulnerability by providing a specially crafted job file that includes the fdp_pli option without an argument. This leads to a NULL pointer dereference, which occurs when the program attempts to access a memory location that has not been assigned, resulting in a segmentation fault and a Denial of Service (DoS) due to a process crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10fioNot affected
Red Hat Enterprise Linux 7fioNot affected
Red Hat Enterprise Linux 8fioNot affected
Red Hat Enterprise Linux 9fioNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2458951fio: fio: Denial of Service via NULL pointer dereference when parsing job files

EPSS

Процентиль: 20%
0.00278
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.

CVSS3: 7.5
nvd
4 месяца назад

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.

CVSS3: 7.5
msrc
3 месяца назад

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.

CVSS3: 7.5
debian
4 месяца назад

A NULL pointer dereference vulnerability exists in fio (Flexible I/O T ...

CVSS3: 7.5
github
4 месяца назад

A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.

EPSS

Процентиль: 20%
0.00278
Низкий

5.5 Medium

CVSS3