CVE-2026-93261: vulnerability in Linux
locking/lockdep: Fix NULL pointer dereference in __lock_set_class()
Published
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
locking/lockdep: Fix NULL pointer dereference in __lock_set_class()
register_lock_class() can return NULL when the lock class pool is
exhausted, graph_lock() fails, or key validation fails. However,
__lock_set_class() uses the return value directly in pointer arithmetic
without a NULL check:
class = register_lock_class(lock, subclass, 0);
hlock->class_idx = class - lock_classes;
If class is NULL, this computes a wild offset that corrupts
hlock->class_idx. The subsequent reacquire_held_locks() call will
invoke hlock_class() with this corrupted index, leading to a NULL or
out-of-bounds pointer dereference.
Add the missing NULL check, consistent with how __lock_acquire() already
handles this case at the same call site.
Affected products
Linux · LinuxRelated CVEs — Linux
In the same product, most dangerous first.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
References
https://git.kernel.org/stable/c/59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2https://git.kernel.org/stable/c/5c3bff6cf26e6a54fbf8b893a879c32824d2d50dhttps://git.kernel.org/stable/c/7577e00b9ab506202b9f1a33de3cc8cc6413a4dbhttps://git.kernel.org/stable/c/9be10f49dfc2e4b472b3a5f346483b67374774b8https://git.kernel.org/stable/c/b2113dcd8238bf00ce37a34e67b29cf31d32a545https://git.kernel.org/stable/c/e7c69c6695d84220847cca62a45e879e71e79e9dhttps://git.kernel.org/stable/c/f56e54fd24f05e9de528fcb77f6084f80c8066cehttps://git.kernel.org/stable/c/f6093ff67ea6e347574819ed23e96e0f82a25ffc