NULL pointer dereference in Linux kernel - #VU133348
Published: June 4, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in drivers/pci/endpoint/functions/pci-epf-vntb.c when handling workqueue allocation failure. A local user can trigger the vulnerable code path to cause a denial of service.
The issue occurs if alloc_workqueue() fails and the code later uses the NULL workqueue pointer.