Improper locking in Linux kernel - CVE-2026-68179
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in nsm_dev_ioctl() in drivers/misc/nsm.c when processing an ioctl request with an invalid user pointer during copy_from_user(). A local user can send a crafted ioctl request to cause a denial of service.
The issue is triggered on the pre-lock error path before the mutex is acquired.