CVE-2026-42800
7.4ASR Microelectronics · Lapwing_Linux
A NULL pointer dereference vulnerability exists within the ims_client modules of ASR Lapwing_Linux, potentially allowing for pointer manipulation.
Executive summary
A NULL pointer dereference vulnerability in ASR Lapwing_Linux could allow a low-privileged attacker to achieve partial system impact, necessitating prompt patching.
Vulnerability
This is a NULL pointer dereference flaw (CWE-476) occurring in the sip/utils/src/sipuri.c file within the ims_client modules. The vulnerability requires the attacker to have low-level authentication to trigger the flaw, according to the CVSS vector.
Business impact
The vulnerability carries a CVSS score of 7.4, indicating high severity. Successful exploitation could lead to partial compromise of confidentiality, integrity, and availability of the affected system, potentially disrupting critical communication services managed by the ims_client modules.
Remediation
Immediate Action: Update the ASR Lapwing_Linux software to the version released on or after April 14, 2026, as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs for unexpected crashes or error messages originating from the ims_client modules or the sipuri.c component.
Compensating Controls: Implement strict network access controls to limit the exposure of the affected modules to trusted users only, thereby reducing the attack surface for low-privileged actors.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for service disruption and the high severity score, administrators should prioritize the deployment of the vendor-provided security update. Ensuring the system is patched to the version dated 2026/4/14 or later is the most effective method to eliminate the risk of pointer manipulation and associated instability.