SB2026090416 - NULL pointer dereference in Linux kernel input joystick driver
Published: September 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-80752)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the psxpad_spi_suspend() function of the psxpad-spi driver when the system suspends. A local user can trigger a system suspend to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1bba6bd6861b1e0c8ecf20cd1892f0d3877c02a2
- https://git.kernel.org/stable/c/1edcb7ffee7ac4dc35cbe5bbd0e27bac3614ebe4
- https://git.kernel.org/stable/c/62e25677d1440085381b047ec4984be9b6793759
- https://git.kernel.org/stable/c/732f38c36059e68ba3b4b89c56911d777fd3185c
- https://git.kernel.org/stable/c/86531cdfb3a03213e2569deed5195412a4e3f7ee
- https://git.kernel.org/stable/c/8d622c58205adbc8af19864e277386528b671345
- https://git.kernel.org/stable/c/da6b8b05db0cf43e0cc198431fa8ee9739b3b817
- https://git.kernel.org/stable/c/e980066e434a9c74ff1665ed9140427e95b0ee7c