{"id":"CVE-2026-93261","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/lockdep: Fix NULL pointer dereference in __lock_set_class()\n\nregister_lock_class() can return NULL when the lock class pool is\nexhausted, graph_lock() fails, or…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/lockdep: Fix NULL pointer dereference in __lock_set_class()\n\nregister_lock_class() can return NULL when the lock class pool is\nexhausted, graph_lock() fails, or…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < f6093ff67ea6e347574819ed23e96e0f82a25ffc","Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < 59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2","Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < f56e54fd24f05e9de528fcb77f6084f80c8066ce","Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < 5c3bff6cf26e6a54fbf8b893a879c32824d2d50d","Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < b2113dcd8238bf00ce37a34e67b29cf31d32a545","Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < e7c69c6695d84220847cca62a45e879e71e79e9d","Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < 9be10f49dfc2e4b472b3a5f346483b67374774b8","Linux >= 64aa348edc617dea17bbd01ddee4e47886d5ec8c < 7577e00b9ab506202b9f1a33de3cc8cc6413a4db","Linux 2.6.27"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T16:17:22.780","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93261","references":[{"url":"https://git.kernel.org/stable/c/59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c3bff6cf26e6a54fbf8b893a879c32824d2d50d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7577e00b9ab506202b9f1a33de3cc8cc6413a4db","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9be10f49dfc2e4b472b3a5f346483b67374774b8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2113dcd8238bf00ce37a34e67b29cf31d32a545","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7c69c6695d84220847cca62a45e879e71e79e9d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f56e54fd24f05e9de528fcb77f6084f80c8066ce","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6093ff67ea6e347574819ed23e96e0f82a25ffc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T16:47:15.835Z","slug":"CVE-2026-93261","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nlocking/lockdep: Fix NULL pointer dereference in __lock_set_class()\n\nregister_lock_class() can return NULL when the lock class pool is\nexhausted, graph_lock() fails, or key validation fails. However,\n__lock_set_class() uses the return value directly in pointer arithmetic\nwithout a NULL check:\n\n  class = register_lock_class(lock, subclass, 0);\n  hlock->class_idx = class - lock_classes;\n\nIf class is NULL, this computes a wild offset that corrupts\nhlock->class_idx. The subsequent reacquire_held_locks() call will\ninvoke hlock_class() with this corrupted index, leading to a NULL or\nout-of-bounds pointer dereference.\n\nAdd the missing NULL check, consistent with how __lock_acquire() already\nhandles this case at the same call site.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}