NULL pointer dereference in Linux kernel - CVE-2026-89442
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the isst_if_clos_assoc ioctl handler when processing a socket ID for an in-range package without a bound TPMI SST instance. A local user can submit a crafted clos_assoc ioctl request to cause a denial of service.