Bug 2513060 (CVE-2026-19411) - CVE-2026-19411 shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL
Summary: CVE-2026-19411 shim/dp.c library: NULL-pointer dereference in is_removable_me...
Keywords:
Status: NEW
Alias: CVE-2026-19411
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-10 09:32 UTC by OSIDB Bzimport
Modified: 2026-08-10 15:11 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-10 09:32:58 UTC
NULL-pointer dereference in `is_removable_media_path()`: when DevicePathToStr() returns `NULL` (e.g. on EFI pool-allocation failure), the result is passed directly to `StrnCaseCmp()`, which dereferences it on the first loop iteration and crashes. This is a 
robustness / defensive-hardening issue -- a missing NULL check on a boot-path helper, rather than an attacker-controlled memory-safety bug.


Note You need to log in before you can comment on or make changes to this bug.