#VU122899 NULL pointer dereference in Linux kernel - CVE-2026-23146
Published: February 16, 2026
Vulnerability identifier: #VU122899
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-23146
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the hci_uart_register_dev() and hci_uart_set_proto() functions in drivers/bluetooth/hci_ldisc.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/03e8c90c62233382042b7bd0fa8b8900552fdb62
- https://git.kernel.org/stable/c/0c3cd7a0b862c37acbee6d9502107146cc944398
- https://git.kernel.org/stable/c/186d147cf7689ba1f9b3ddb753ab634a84940cc9
- https://git.kernel.org/stable/c/53e54cb31e667fca05b1808b990eac0807d1dab0
- https://git.kernel.org/stable/c/937a573423ce5a96fdb1fd425dc6b8d8d4ab5779
- https://git.kernel.org/stable/c/b0a900939e7e4866d9b90e9112514b72c451e873
- https://git.kernel.org/stable/c/ccc683f597ceb28deb966427ae948e5ac739a909