#VU124498 NULL Pointer Dereference in Linux kernel - CVE-2026-23341
Published: March 25, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the accel/amdxdna driver when destroying a hardware context that has been suspended. A local user can send a specially crafted ioctl request to trigger access to a NULL mailbox channel pointer, leading to a system crash.
The attacker must have the ability to open and control AMD XDNA device contexts, which typically requires access to the device file and appropriate permissions.