NULL pointer dereference in Linux kernel - CVE-2026-93038
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the ad5686 SPI and I2C driver probe routines when binding the driver through driver_override in sysfs with a device name absent from the ID and match tables. A local privileged user can bind the driver using such a device name to cause a denial of service.