CVE-2026-68434

Summary

In the Linux kernel, the following vulnerability has been resolved:

serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms

Commit b1b4efea05a5 ("serial: 8250_mid: Disable DMA for selected platforms") replaced the dnv_board setup and exit callbacks with PTR_IF(false, …), which evaluates to NULL. However, the three call sites in mid8250_probe() and mid8250_remove() unconditionally dereference these function pointers without NULL checks, causing a NULL pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon D (ICX-D/CDF), or Snowridge (SNR) platform.

Fix this by adding the missing NULL checks before calling the setup and exit callbacks.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6 < 1096397c31f6bffa95e77bdd18fbca085be83e10affected
LinuxLinux977855894bca4b87afa50d21e3f3e85a5a0e901f < 600dcd548fb2b00a69f447684f52ba45d5a3540eaffected
LinuxLinux1cd54e217c6e2cdb794a897b2f855e13ffcee586 < b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56affected
LinuxLinux9690e8a342632344984af72bc56b7a1fba61e6cb < 8cbad52ccfa6a7f089cfab34979bc6cc3bff25beaffected
LinuxLinuxb1b4efea05a56c0995e4702a86d6624b4fdff32f < 7fb13fd7e9a59a37cd911efff83abe19e3ee029daffected
LinuxLinux763d61ded752fbb3116efc951eff4363f237b7e0affected
LinuxLinuxc7d190bb07bf4e3b217c69370e94d1b4c80a40adaffected
LinuxLinux0b3ed3fa227ba778cabed96e7f8d84addb8bdf9caffected
LinuxLinux6.6.145 < 6.6.148affected
LinuxLinux6.12.96 < 6.12.101affected
LinuxLinux6.18.39 < 6.18.42affected
LinuxLinux7.1.4 < 7.1.6affected
LinuxLinux5.10.261 < 5.11affected
LinuxLinux5.15.212 < 5.16affected
LinuxLinux6.1.178 < 6.2affected
LinuxLinux7.2-rc3affected
LinuxLinux0 < 7.2-rc3unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References