NULL pointer dereference in Linux kernel - CVE-2026-80813
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in nvmet_execute_identify_nslist() when processing an Identify command with CNS 07h. A remote attacker can issue a crafted Identify command to cause a denial of service.
Exploitation requires an enabled namespace with an NSID greater than the requested value.