SB20260925120 - NULL pointer dereference in Linux kernel locking
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-93261)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a missing null check in __lock_set_class() when register_lock_class() returns NULL. A local user can cause lock class registration to fail to cause a denial of service.
Lock class registration can fail when the lock class pool is exhausted, graph_lock() fails, or key validation fails.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2
- https://git.kernel.org/stable/c/5c3bff6cf26e6a54fbf8b893a879c32824d2d50d
- https://git.kernel.org/stable/c/7577e00b9ab506202b9f1a33de3cc8cc6413a4db
- https://git.kernel.org/stable/c/9be10f49dfc2e4b472b3a5f346483b67374774b8
- https://git.kernel.org/stable/c/b2113dcd8238bf00ce37a34e67b29cf31d32a545
- https://git.kernel.org/stable/c/e7c69c6695d84220847cca62a45e879e71e79e9d
- https://git.kernel.org/stable/c/f56e54fd24f05e9de528fcb77f6084f80c8066ce
- https://git.kernel.org/stable/c/f6093ff67ea6e347574819ed23e96e0f82a25ffc