NULL pointer dereference in Linux kernel - CVE-2026-89460
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the s390 CPUMF performance monitoring unit when a CPU is added while a per-task CPUMF performance event is running. A local privileged user can trigger CPU hotplug during execution of a per-task performance event to cause a denial of service.