NULL pointer dereference in Linux kernel - CVE-2026-80648
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in spacemit_pin_set_config when handling an invalid pin identifier. A local user can trigger the vulnerable code path to cause a denial of service.
The issue stems from checking the pin id variable instead of the pointer returned by spacemit_get_pin().