NULL pointer dereference in Linux kernel - CVE-2026-80658
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in dw_dp_remove() in the Rockchip DRM dw_dp driver when removing a platform device. A local user can trigger device removal in a state where driver data was not initialized to cause a denial of service.
This can occur when the component bind callback did not run before the remove callback is invoked.