You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026 23285
About this tag
CVE-2026-23285 is a Linux kernel vulnerability in DRBD (Distributed Replicated Block Device) that causes a null-pointer dereference on local read error. The issue occurs when a read-completion path passes a NULL peer_device pointer to __req_mod(), leading to a crash in error-handling code. The upstream patch fixes this by ensuring proper pointer validation. This tag covers discussions about the vulnerability, its impact on DRBD replication, and the fix. While the vulnerability is in the Linux kernel, it may affect Windows systems running DRBD in virtualized or WSL environments.
Background
Microsoft’s Security Response Guide entry for CVE-2026-23285 points to a Linux kernel issue in DRBD: a null-pointer dereference on local read error. The upstream patch title is unambiguous enough to tell the story at a glance: drbd: fix null-pointer dereference on local read error...