Executive brief
A vulnerability in the Linux kernel's GPIO (General Purpose Input/Output) subsystem could cause a system crash. The issue occurs when the system attempts to log a debug message using a pointer that has already been cleared. This could lead to a denial-of-service condition where the operating system stops functioning unexpectedly.
Technical details
A NULL pointer dereference exists in the `linehandle_create()` function within `drivers/gpio/gpiolib-cdev.c`. The vulnerability is triggered when a debug print statement (`dev_dbg`) attempts to access `lh->num_descs` after the `lh` pointer has been cleared by `retain_and_null_ptr(lh)`. An attacker with local access could potentially trigger this crash by interacting with the GPIO character device interface. The fix involves using `handlereq.lines` instead of the dereferenced pointer for the debug output. Patches have been merged into the stable kernel tree.
Affected products
- Linux Linux Kernel All versions prior to the fix in gpiolib-cdev.c
Timeline
- 2026-02-15: other: Patch submitted by developer
- 2026-06-03: advisory: CVE published to NVD