NULL pointer dereference in Linux kernel - CVE-2026-90080
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the OcteonTX2 PF driver's af_xdp_zc_qidx bitmap handling when switching devlink eswitch mode. A local privileged user can switch devlink eswitch mode to dereference a NULL bitmap and cause a denial of service.