Junglewise Threat Intelligence

CVE-2026-68434: Linux kernel 8250_mid NULL function pointer dereference on DNV/ICX-D/SNR

CVE-2026-68434 · Severity: info · CVSS 0 · Published 2026-08-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's serial 8250 driver for Intel Data Center platforms (Denverton, Ice Lake Xeon D, and Snowridge) crashes during device probe or removal due to a missing NULL pointer check. A code refactoring inadvertently set function pointers to NULL, but the driver still attempts to call them without checking, causing an immediate system crash (kernel oops) on affected platforms.

Technical details

This is a null pointer dereference bug in the 8250_mid serial driver. Commit b1b4efea05a5 disabled DMA for certain platforms by setting setup and exit callbacks to NULL via PTR_IF(false, ...), but three call sites in mid8250_probe() and mid8250_remove() unconditionally dereference these pointers without NULL checks. The vulnerability affects Denverton (DNV), Ice Lake Xeon D (ICX-D/CDF), and Snowridge (SNR) platforms. An attacker with ability to cause device probe/removal (e.g., via device hotplug or module load on an affected system) triggers the NULL dereference, causing a kernel panic/denial of service. The fix adds conditional checks before each function pointer dereference.

Affected products

  • Linux Linux kernel 5.x, 6.x, 7.x (versions after commit b1b4efea05a5)

Timeline

  • 2026-08-12: disclosed
  • 2026-08-03: patched: Fix committed upstream and backported to stable trees

References

Related threats