NULL Pointer Dereference in Linux Kernel Affecting 32-Bit Systems
CVE-2026-80917

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-80917?

A vulnerability in the Linux kernel affects 32-bit systems using the 'pci-host-cam-generic' configuration. Due to an inability to set up a proper per-bus mapping, a NULL pointer dereference occurs during PCI bus enumeration, which can lead to system crashes. The vulnerability stems from the missing ->add_bus and ->remove_bus callbacks for the CAM operations, which resulted in a crash when the system attempted to read from a NULL base address. This issue has been addressed by aligning the CAM ops with necessary callbacks to prevent such dereferences in the future.

Affected Version(s)

Linux 8fe55ef23387ce3c7488375b1fd539420d7654bb < 5e52eb0290f66ba0732956dcb1e365b5ca3c5108

Linux 8fe55ef23387ce3c7488375b1fd539420d7654bb

Linux 8fe55ef23387ce3c7488375b1fd539420d7654bb < 8d08713ec83a18526d1ed1fd5f0d2b901d103a10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.