SB20260917146 - NULL pointer dereference in Linux kernel drm i915 driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-89822)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in i915_pci_probe() when a device is force-bound through the sysfs driver_override interface. A local user can force-bind a device to the i915 driver to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18b3433f10ee9c69e3252046028aa2be421f2d4d
- https://git.kernel.org/stable/c/2239e6b49d33bb38817d69b4f0bf7d5cbde2ec68
- https://git.kernel.org/stable/c/3785d40831ba5601296283e0197e10e089392757
- https://git.kernel.org/stable/c/4a0236fe97732e31cb4a6dcb433642f9e3ef9a56
- https://git.kernel.org/stable/c/84829e324a396668ceafb14723293b2863a74dcf
- https://git.kernel.org/stable/c/e351cb2d373f6f1d4f1eb7c9f30dc058c69c89f8