CVE-2026-93261
CVE CVE-2026-93261EUVD EUVD-2026-86133Published 2026-09-24T15:51:59.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: locking/lockdep: Fix NULL pointer dereference in __lock_set_class() register_lock_class() can return NULL when the lock class pool is exhausted, graph_lock() fails, or key validation fails. However, __lock_set_class() uses the return value directly in pointer arithmetic without a NULL check: class = register_lock_class(lock, subclass, 0); hlock->class_idx = class - lock_classes; If class is NULL, this computes a wild offset that corrupts hlock->class_idx. The subsequent reacquire_held_locks() call will invoke hlock_class() with this corrupted index, leading to a NULL or out-of-bounds pointer dereference. Add the missing NULL check, consistent with how __lock_acquire() already handles this case at the same call site.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 64aa348edc617dea17bbd01ddee4e47886d5ec8c <b2113dcd8238bf00ce37a34e67b29cf31d32a545; 64aa348edc617dea17bbd01ddee4e47886d5ec8c <7577e00b9ab506202b9f1a33de3cc8cc6413a4db; patch: 7.2.6; 64aa348edc617dea17bbd01ddee4e47886d5ec8c <59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2; patch: 0; patch: 5.15.221; patch: 5.10.270; patch: 6.12.110; patch: 6.6.157; 64aa348edc617dea17bbd01ddee4e47886d5ec8c <f6093ff67ea6e347574819ed23e96e0f82a25ffc; 64aa348edc617dea17bbd01ddee4e47886d5ec8c <f56e54fd24f05e9de528fcb77f6084f80c8066ce; patch: 6.18.52; 64aa348edc617dea17bbd01ddee4e47886d5ec8c <e7c69c6695d84220847cca62a45e879e71e79e9d; 64aa348edc617dea17bbd01ddee4e47886d5ec8c <9be10f49dfc2e4b472b3a5f346483b67374774b8; patch: 6.1.188; patch: 7.3-rc1; 2.6.27; 64aa348edc617dea17bbd01ddee4e47886d5ec8c <5c3bff6cf26e6a54fbf8b893a879c32824d2d50d
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.