#VU124903 NULL pointer dereference in Linux kernel - CVE-2026-23467

 

#VU124903 NULL pointer dereference in Linux kernel - CVE-2026-23467

Published: April 6, 2026


Vulnerability identifier: #VU124903
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-23467
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the intel_dmc_update_dc6_allowed_count() function when initializing display power management during device probe. A local user can trigger the vulnerable code path to cause a denial of service.

The issue occurs when DMC has not been initialized and the dmc pointer is NULL. It is triggered only under specific DC state conditions during probe, making the failure mode unlikely.


Remediation

Install security update from vendor's repository.

External links