NULL pointer dereference in Linux kernel - CVE-2026-43013
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in mlx5_ldev_add_debugfs() when accessing debugfs entries created without a valid LAG context. A local user can access a specially exposed debugfs interface to cause a denial of service.
The issue occurs when debugfs entries are created even though no valid ldev pointer is available.
How to mitigate CVE-2026-43013
Sources
- https://git.kernel.org/stable/c/7129632cab3e4d23510b21930aa73b8d97a859f5
- https://git.kernel.org/stable/c/89c65f2fcd8801365b410f40a427cbcd7f4c28e9
- https://git.kernel.org/stable/c/a3db46d5f4df92630a96f7bc77b60e75c2353e06
- https://git.kernel.org/stable/c/bf16bca6653679d8a514d6c1c5a2c67065033f14
- https://git.kernel.org/stable/c/c53cf44588a93000f71817a6bb87a66353c48dee
- https://git.kernel.org/stable/c/cfa774e6c920c81e700327bf10db8cb50d5db456