NULL pointer dereference in Linux kernel - CVE-2026-97414
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the mt8365_afe_suspend() function of the MediaTek MT8365 AFE PCM driver when handling a suspend operation after register backup buffer allocation fails. A local user can trigger a suspend operation when register backup buffer allocation fails to cause a denial of service.
The runtime-suspend state may be updated even when the suspend operation fails.