Junglewise Threat Intelligence

CVE-2026-92479: Linux kernel UFS NULL pointer dereference in completion handling

CVE-2026-92479 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's UFS (Ultra FS) storage driver contains a potential null pointer dereference bug in its completion queue event handler. When processing invalid completion tags from storage devices, the error reporting code could crash the kernel if it attempts to access a null completion queue entry, resulting in system instability or denial of service on servers using UFS storage.

Technical details

The vulnerability is a null pointer dereference in the `ufshcd_compl_one_cqe()` function within the UFS host controller driver. When the single-doorbell completion path receives an invalid completion tag with no associated command, the WARN_ONCE() macro attempted to dereference a NULL CQE (completion queue entry) pointer while constructing the warning message. The fix adds a null check (`cqe ?`) before dereferencing the pointer and includes the invalid tag value in the error message. This is a defensive programming fix rather than a critical exploitable vulnerability; local code execution or denial of service would require triggering this specific error path through malformed device responses or kernel manipulation.

Affected products

  • Linux Linux kernel affected versions including 6.0 through 6.19 and 5.x series

Timeline

  • 2026-09-17: disclosed
  • 2026-07-26: patched

References

Related threats