#VU124199 NULL Pointer Dereference in Linux kernel - CVE-2026-23249

 

#VU124199 NULL Pointer Dereference in Linux kernel - CVE-2026-23249

Published: March 20, 2026


Vulnerability identifier: #VU124199
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-23249
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a null pointer dereference in the XFS filesystem's btree revalidation functionality when handling ioctl requests. A local user can trigger a specially crafted ioctl request to cause a null pointer dereference and crash the system.

The attacker must have privileges to perform XFS filesystem scrub operations, which typically requires administrative privileges.


Remediation

Install security update from vendor's repository.

External links