NULL Pointer Dereference in Linux Kernel Affects Firmware Management
CVE-2026-80577

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80577?

A vulnerability in the Linux kernel during firmware management permits zero-sized firmware sections to be added without proper handling. The function panthor_fw_load_section_entry() was modified to skip creating buffer objects (BO) when a firmware section's virtual address range is empty. However, if an entry with a zero-sized section is included, it may result in a NULL pointer dereference in subsequent operations that access the firmware sections. This oversight can lead to potential instability and exposure to various risks for systems utilizing affected kernel versions.

Affected Version(s)

Linux 2718d91816eeed03c09c8abe872e45f59078768c

Linux 2718d91816eeed03c09c8abe872e45f59078768c < 25556a46ae6ecf2a9f1c1c5096828eecd4596b91

Linux 2718d91816eeed03c09c8abe872e45f59078768c < 5d222b657f02a37f658e4e21925b85b4703855e7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.