HIGH
fio: fio: Denial of Service via NULL pointer dereference when parsing job files
Published Apr 16, 2026
7.5
HIGHCVSS 3.1
EPSS 0.49%
Description
A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 10
fio
Not affected
Red Hat Enterprise Linux 7
fio
Not affected
Red Hat Enterprise Linux 8
fio
Not affected
Red Hat Enterprise Linux 9
fio
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | fio | Not affected | n/a |
| Red Hat Enterprise Linux 7 | fio | Not affected | n/a |
| Red Hat Enterprise Linux 8 | fio | Not affected | n/a |
| Red Hat Enterprise Linux 9 | fio | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2026-30656 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2458951 Issue Tracking
- https://gist.github.com/Criticayon/eb5e69163bfa4ce684e62ed5c939b76e
- https://github.com/axboe/fio/issues/2055
- https://nvd.nist.gov/vuln/detail/CVE-2026-30656
- https://www.cve.org/CVERecord?id=CVE-2026-30656
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 16, 2026
Updated Apr 16, 2026
Reserved Mar 4, 2026
Link CVE-2026-30656
CISA Vulnrichment
Updated Apr 16, 2026