CVE-2026-30656 is a NULL pointer dereference vulnerability affecting fio (Flexible I/O Tester) version 3.41 and potentially other versions. The flaw exists in the str_fdp_pli_cb() callback function, which fails to validate input pointers before calling strdup() on the fdp_pli option when specified without an argument in job configuration files. This parsing defect triggers a segmentation fault, causing the fio process to crash. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-accessible attack vector requiring no authentication or user interaction, though it is limited to availability impact only. An attacker can exploit this by crafting a malicious job file and providing it to a fio instance, potentially disrupting I/O testing operations or service availability in environments where fio processes untrusted configuration inputs. This vulnerability is not currently listed in the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild. No public exploit code has been identified, and community attention remains minimal as indicated by its Inactive Hot List status. Organizations using fio should apply patches when available, with priority based on whether they process untrusted job files.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.