NULL Pointer Dereference in Linux kernel - CVE-2026-23251
Published: March 20, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the XFS filesystem component when handling file operations. A local user can trigger improper pointer management to cause a denial of service.
The vulnerability specifically involves calling destructors on invalid pointers in the xfarray and xfblob structures, which can lead to system instability or crash.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-23251
linux (Debian package) - update to 6.12.85-1