NULL pointer dereference in Linux kernel - CVE-2026-89439
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the isst_if_get_tpmi_instance_count function in the ISST TPMI core when handling a TPMI instance-count request for a socket whose instance failed to load. A local user can request an instance count for a socket whose instance failed to load to cause a denial of service.