SB20260812286 - NULL pointer dereference in Linux kernel drm i915 driver
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-68248)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in active_instance in the i915 DRM driver when handling memory allocation failure during GFP_ATOMIC allocation. A local user can trigger the vulnerable code path to cause a denial of service.
The issue occurs when kmem_cache_alloc returns NULL and the function returns node->base derived from a NULL node.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1e33f0de5fdcd09e51fdec1e5822448970b6420f
- https://git.kernel.org/stable/c/32c1a2afa90dd07df931f0b12578de1dbb751f0c
- https://git.kernel.org/stable/c/58b7e63ca0cd964190957ddd169c899256acaee9
- https://git.kernel.org/stable/c/b238d86e7f43afde8e830ef5b8d89ffedbbc7613
- https://git.kernel.org/stable/c/cbec6a57959ab503e3ad4ad6edd51efb585dce92