NULL pointer dereference in Linux kernel - CVE-2026-97506
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to trigger a null-pointer dereference.
The vulnerability exists due to improper handling of an allocation failure in chainup_buffers() in the ixp4xx crypto driver when constructing a buffer descriptor chain for a scatterlist. A local user can submit a crypto request that encounters an allocation failure to trigger a null-pointer dereference.