CVE-2026-8035

Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ni:ni-pal:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ni:linux_real-time:-:*:*:*:*:*:*:*

History

05 Jun 2026, 15:11

Type Values Removed Values Added
First Time Ni linux Real-time
Ni
Linux linux Kernel
Microsoft windows
Linux
Microsoft
Ni ni-pal
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/invalid-input-validation-vulnerabilities-in-ni-pal.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/invalid-input-validation-vulnerabilities-in-ni-pal.html - Vendor Advisory
CPE cpe:2.3:a:ni:ni-pal:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:ni:linux_real-time:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

02 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 20:16

Updated : 2026-06-05 15:11


NVD link : CVE-2026-8035

Mitre link : CVE-2026-8035

CVE.ORG link : CVE-2026-8035


JSON object : View

Products Affected

ni

  • linux_real-time
  • ni-pal

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference