NULL pointer dereference in Linux kernel - CVE-2026-52922
Published: June 25, 2026
Vulnerability identifier: #VU135450
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-52922
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in batadv_dat_forward_data() when forwarding data to DHT candidates. A local attacker can trigger an allocation failure and reach unconditional dereference of a NULL skb pointer to cause a denial of service.
How to mitigate CVE-2026-52922
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/2d8826a2d3657cea66fb0370f9e521575a673871
- https://git.kernel.org/stable/c/2edb8aeb3cdda9d00ec4997252dc5bcd6f54d8ef
- https://git.kernel.org/stable/c/4d420d9ee70a220a2cd95aa0dd2e15acad66a505
- https://git.kernel.org/stable/c/866ac1d57040ed0b44ca732e3c66b3aa6b93011c
- https://git.kernel.org/stable/c/9bcebaedfb8479cb4affb23c7a0d000ca9a20e73
- https://git.kernel.org/stable/c/9cceea8eeba710def2a5707ee00f00c74a9a1cac
- https://git.kernel.org/stable/c/ce0c381199402a2c58f4599f4f6ed100d872d0da
- https://git.kernel.org/stable/c/cf48e75fc4fe0d5cc7721c82d454221d01367b93