CVE-2026-89552Medium· 4.1▾ SunlitA flaw was found in the Linux kernel. When updating charp parameters, an allocation failure can cause the parameter to be set to NULL before the new value is successfully allocated. This can lead to a kernel NULL pointer dereference, which…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.1
none → medium
— → 4.1
none → medium
Last analysed / modified upstream
— → 4.1
none → medium
A flaw was found in the Linux kernel. When updating charp parameters, an allocation failure can cause the parameter to be set to NULL before the new value is successfully allocated. This can lead to a kernel NULL pointer dereference, which may result in a system crash and a denial of service.
kernel: Linux kernel: Denial of Service via NULL pointer dereference in parameter handling — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.
Affected:
No fix planned:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80954Medium· 5.5kernel: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() (CVE-2026-80954)
CVE-2026-89509Medium· 5.5kernel: RDMA/ionic: Embed counter driver data in rdma_counter allocation (CVE-2026-89509)
CVE-2026-89517Medium· 5.5kernel: sched_ext: Fix rq->core_pick corruption under core scheduling (CVE-2026-89517)
CVE-2026-89591Medium· 5.5kernel: accel/rocket: initialize job domain before cleanup paths (CVE-2026-89591)
CVE-2026-89592Medium· 5.5kernel: accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() (CVE-2026-89592)
CVE-2026-89734Medium· 5.5kernel: usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() (CVE-2026-89734)