SB2026082760 - NULL pointer dereference in Linux kernel drm panthor driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-80577)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in panthor firmware section handling in panthor_fw_load_section_entry() and related reload and unplug paths when processing zero-sized firmware sections. A local user can provide a crafted firmware image containing an empty section entry to cause a denial of service.
Zero-sized firmware sections are valid inputs, and the issue is triggered when such an entry is left in the firmware section list with an unset memory pointer.
Remediation
Install update from vendor's website.