CVE-2026-93261

medium

Description

In the Linux kernel, the following vulnerability has been resolved: locking/lockdep: Fix NULL pointer dereference in __lock_set_class() register_lock_class() can return NULL when the lock class pool is exhausted, graph_lock() fails, or key validation fails. However, __lock_set_class() uses the return value directly in pointer arithmetic without a NULL check: class = register_lock_class(lock, subclass, 0); hlock->class_idx = class - lock_classes; If class is NULL, this computes a wild offset that corrupts hlock->class_idx. The subsequent reacquire_held_locks() call will invoke hlock_class() with this corrupted index, leading to a NULL or out-of-bounds pointer dereference. Add the missing NULL check, consistent with how __lock_acquire() already handles this case at the same call site.

References

https://git.kernel.org/stable/c/f6093ff67ea6e347574819ed23e96e0f82a25ffc

https://git.kernel.org/stable/c/f56e54fd24f05e9de528fcb77f6084f80c8066ce

https://git.kernel.org/stable/c/e7c69c6695d84220847cca62a45e879e71e79e9d

https://git.kernel.org/stable/c/b2113dcd8238bf00ce37a34e67b29cf31d32a545

https://git.kernel.org/stable/c/9be10f49dfc2e4b472b3a5f346483b67374774b8

https://git.kernel.org/stable/c/7577e00b9ab506202b9f1a33de3cc8cc6413a4db

https://git.kernel.org/stable/c/5c3bff6cf26e6a54fbf8b893a879c32824d2d50d

https://git.kernel.org/stable/c/59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2

Details

Source: Mitre, NVD

Published: 2026-09-24

Updated: 2026-09-24

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00196