NULL pointer dereference in Linux kernel - CVE-2026-89484
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in nlmclnt_locks_release_private() when releasing a partially initialized file_lock after lockowner allocation failure. A local user can trigger a lockowner allocation failure during NLM file lock initialization to cause a denial of service.
The VFS may release the partially initialized file lock after NLM client processing returns an out-of-memory error.