CVE-2026-68176

Summary

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev

If the mmio_pipe_open() fails to find a PCI device, the hiter->dev will be assigned to NULL. The mmiotrace read() function dereferences the hiter->dev if hiter exists.

Change the test of the read to not only check hiter being NULL, but also the hiter->dev before dereferencing it.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf984b51e0779a6dd30feedc41404013ca54e5d05 < faaf95135184208ee3ac6f33175c8d1800669dfcaffected
LinuxLinuxf984b51e0779a6dd30feedc41404013ca54e5d05 < 201a01102c529772168181190cb084471082cf5caffected
LinuxLinuxf984b51e0779a6dd30feedc41404013ca54e5d05 < 8464427e1c177809a9488a97dfa2807d9dcf323baffected
LinuxLinuxf984b51e0779a6dd30feedc41404013ca54e5d05 < 724cd84b0546c07806840fa658714488553d13a2affected
LinuxLinuxf984b51e0779a6dd30feedc41404013ca54e5d05 < 144f29e85702234b23d2a62abf723e6a17eb5427affected
LinuxLinux2.6.27affected
LinuxLinux0 < 2.6.27unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References