NULL pointer dereference in Linux kernel - CVE-2026-72485
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of allocation failure in coresight platform connection management functions when processing device probe data. A local user can trigger memory allocation failure during probe cleanup to cause a denial of service.
The issue occurs because cleanup code iterates connection entries up to inconsistent counter values and dereferences NULL or uninitialized pointers, leading to a kernel panic.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-72485
linux (Debian package) - update to 6.12.111-1