NULL pointer dereference in Linux kernel - CVE-2026-31540
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the i915 driver suspend handling path when suspending a system without i915 driver firmware binaries present. A local user can trigger a suspend operation to cause a denial of service.
The issue occurs because the set_default_submission function pointer may be unset and still dereferenced during suspend.
How to mitigate CVE-2026-31540
Sources
- https://git.kernel.org/stable/c/0162ab3220bac870e43e229e6e3024d1a21c3f26
- https://git.kernel.org/stable/c/1a16150729db8d997e39519f9d58e6b435c4c087
- https://git.kernel.org/stable/c/2e20a886b443a71b573ceaed3ca7053d15380916
- https://git.kernel.org/stable/c/cf4b224ffb9a58181be32b64130fc36cf59c3192
- https://git.kernel.org/stable/c/da6552d67012a1cf0585f2eb401d0c4abcf108c9
- https://git.kernel.org/stable/c/db8b1bebe81ffb410ddd746b6869f72e22420850
- https://git.kernel.org/stable/c/df1f4a7d9cf689b4e96c95255228896505f44c31