NULL pointer dereference in Linux kernel - CVE-2026-92492
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the amd-pstate dynamic EPP callbacks when a racing CPU hotplug or driver teardown leaves no cpufreq policy associated with the requested CPU. A local user can trigger a dynamic EPP callback during the race to cause a denial of service.