{"id":"CVE-2026-93261","published":"2026-09-24T16:17:22.780","lastModified":"2026-09-24T16:17:22.780","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/lockdep: Fix NULL pointer dereference in __lock_set_class()\n\nregister_lock_class() can return NULL when the lock class pool is\nexhausted, graph_lock() fails, or key validation fails. However,\n__lock_set_class() uses the return value directly in pointer arithmetic\nwithout a NULL check:\n\n  class = register_lock_class(lock, subclass, 0);\n  hlock->class_idx = class - lock_classes;\n\nIf class is NULL, this computes a wild offset that corrupts\nhlock->class_idx. The subsequent reacquire_held_locks() call will\ninvoke hlock_class() with this corrupted index, leading to a NULL or\nout-of-bounds pointer dereference.\n\nAdd the missing NULL check, consistent with how __lock_acquire() already\nhandles this case at the same call site.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/59a5c7dd331a3dab48100e1ef8e9bb4f9132a2b2","tags":[]},{"url":"https://git.kernel.org/stable/c/5c3bff6cf26e6a54fbf8b893a879c32824d2d50d","tags":[]},{"url":"https://git.kernel.org/stable/c/7577e00b9ab506202b9f1a33de3cc8cc6413a4db","tags":[]},{"url":"https://git.kernel.org/stable/c/9be10f49dfc2e4b472b3a5f346483b67374774b8","tags":[]},{"url":"https://git.kernel.org/stable/c/b2113dcd8238bf00ce37a34e67b29cf31d32a545","tags":[]},{"url":"https://git.kernel.org/stable/c/e7c69c6695d84220847cca62a45e879e71e79e9d","tags":[]},{"url":"https://git.kernel.org/stable/c/f56e54fd24f05e9de528fcb77f6084f80c8066ce","tags":[]},{"url":"https://git.kernel.org/stable/c/f6093ff67ea6e347574819ed23e96e0f82a25ffc","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}