NULL pointer dereference in Linux kernel - CVE-2026-43364
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in ublk_ctrl_set_size() when handling UBLK_CMD_UPDATE_SIZE requests for a device that has not yet been started or has already been stopped. A local user can send a crafted UPDATE_SIZE command to cause a denial of service.
The issue can be triggered before UBLK_CMD_START_DEV completes or after UBLK_CMD_STOP_DEV runs.