NULL pointer dereference in Linux kernel - CVE-2026-80651
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in dsm_create() in drivers/crypto/ccp/sev-dev-tsm.c when handling a pci device with a NULL bus pointer. A local user can trigger the vulnerable code path to cause a denial of service.
The issue crashes the kernel before SEV TIO setup can proceed.