CVE-2026-8035 Details
Description
Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
A denial-of-service vulnerability has been identified in the NI-PAL kernel driver, affecting versions through 26.3.0 on Windows, Linux, and Linux Real-Time. The issue arises from improper input validation, which may allow a local authenticated user to cause a crash by triggering a NULL pointer dereference.
Users are advised to upgrade to NI-PAL version 26.3.1 or later. For Windows, this can be done by installing NI-VISA 2026 Q2 Patch 1 or later. On Linux desktops, NI Linux Device Drivers 2026 Q2 or later should be installed. For NI Linux Real-Time, NI Linux RT System Image 2026 Q2 or later is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni ni-pal | <= 26.3.0 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| ni linux real-time | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | New CVE Received | [email protected] |