NULL pointer dereference in Linux kernel - CVE-2026-90335
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in tty_unregister_device when removing a TTY device after device registration fails before a character device is allocated. A local user can trigger device removal after a failed TTY device registration to cause a denial of service.