NULL pointer dereference in Linux kernel - CVE-2026-89851
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in qla2x00_dfs_fce_write() when parsing a value written to the debugfs FCE trace interface. A local user can write a valid numeric value to the interface to cause a denial of service.
Invalid values can unintentionally enable FCE tracing.
Affected software
How to mitigate CVE-2026-89851
External References
- https://git.kernel.org/stable/c/5762d992dddaf301e7fb78f797de407116847121
- https://git.kernel.org/stable/c/7203d4aed8f444e7376c2dee8d93577b37cf9989
- https://git.kernel.org/stable/c/9932cbd0b49d0a5ab8378d32650ffb51604ffa35
- https://git.kernel.org/stable/c/aac0d3cb9199121d2ce5906e06f94b793fac1052
- https://git.kernel.org/stable/c/b0c08c08a08b6cca0e7e192bcbe0514e41fcc55f
- https://git.kernel.org/stable/c/b7368687e3d11f51392d3c4774ec0263d5fbf31f
- https://git.kernel.org/stable/c/eff41f50461c238bd2c5cd20672a5b53e68d493a
- https://git.kernel.org/stable/c/f5e245164d187d1ee227140c8b2e83b67f59c1fd