NULL pointer dereference in Linux kernel - CVE-2026-80697
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in erofs page cache sharing handling when processing mincore requests against backing files with an empty f_path. A local user can trigger the vulnerable code path to cause a denial of service.
The issue occurs because backing files used for page cache sharing were created with only f_inode set while f_path remained NULL.