NULL pointer dereference in Linux kernel - CVE-2026-53142

 

NULL pointer dereference in Linux kernel - CVE-2026-53142

Published: June 26, 2026


Vulnerability identifier: #VU135646
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53142
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the xe display initialization and cleanup logic when handling suspend or shutdown on systems without display hardware present. A local user can trigger suspend or shutdown processing to cause a denial of service.

The issue occurs when display support is probed but display hardware is later determined to be unavailable or disabled at runtime initialization.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-53142

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.95-1

External References

Related Security Bulletins