NULL pointer dereference in Linux kernel - CVE-2026-89457
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in s390 DASD sysfs discipline callbacks when reading world-readable sysfs attributes during device initialization. A local user can read a sysfs attribute before private device data is allocated to trigger a kernel panic and cause a denial of service.