NULL Pointer Dereference in Linux Kernel Affects Firmware Management
CVE-2026-80577
What is CVE-2026-80577?
A vulnerability in the Linux kernel during firmware management permits zero-sized firmware sections to be added without proper handling. The function panthor_fw_load_section_entry() was modified to skip creating buffer objects (BO) when a firmware section's virtual address range is empty. However, if an entry with a zero-sized section is included, it may result in a NULL pointer dereference in subsequent operations that access the firmware sections. This oversight can lead to potential instability and exposure to various risks for systems utilizing affected kernel versions.
Affected Version(s)
Linux 2718d91816eeed03c09c8abe872e45f59078768c
Linux 2718d91816eeed03c09c8abe872e45f59078768c < 25556a46ae6ecf2a9f1c1c5096828eecd4596b91
Linux 2718d91816eeed03c09c8abe872e45f59078768c < 5d222b657f02a37f658e4e21925b85b4703855e7