NULL pointer dereference in Linux kernel - CVE-2026-80743

 

NULL pointer dereference in Linux kernel - CVE-2026-80743

Published: September 4, 2026


Vulnerability identifier: #VU146922
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80743
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper initialization of IRQ handler data in the Xilinx formatter PCM IRQ handlers when an interrupt occurs after IRQ registration and before driver data is set. A local user can trigger an interrupt during device probing to cause a denial of service.


Affected software

Linux kernel

How to mitigate CVE-2026-80743

Install security update from vendor's repository.


External References

Related Security Bulletins