SB2026072161 - NULL pointer dereference in Linux kernel test-drivers vidtv driver
Published: July 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-53382)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in vidtv_mux_push_si when handling PID contexts during stream information processing. A local user can trigger allocation failure conditions that leave a PID context unset to cause a denial of service.
The issue can lead to a general protection fault in the vidtv test driver workqueue path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/232e4b313ea342672edf8947e067c0de4328405b
- https://git.kernel.org/stable/c/353d9578951dd38bc9679308f5b618ceed1f20fa
- https://git.kernel.org/stable/c/455bc12e7b73ab5a2dfcb47822e91e772bc6c42e
- https://git.kernel.org/stable/c/6df7e16d4f742c80add58995a6e69385b97aa9e6
- https://git.kernel.org/stable/c/7d8bf3d8f91073f4db347ed3aa6302b56107499c
- https://git.kernel.org/stable/c/b28b12be6e8910489e6800ed93ea4d41dfe19683
- https://git.kernel.org/stable/c/cd923dadefadb9671b5ac341b672ff424d429c39
- https://git.kernel.org/stable/c/f0f5a1d7056980a0d512456fdb370cfb72bba86a
- https://git.kernel.org/stable/c/f965cf22dda7f512f4922415894c3e528269a4ae