Junglewise Threat Intelligence

CVE-2026-93261: In the Linux kernel, the following vulnerability has been resolved: locking/lockdep: Fix NULL pointer dereference in __lock_set_class() re

CVE-2026-93261 · Severity: info · Published 2026-09-24

Executive brief

In the Linux kernel, the following vulnerability has been resolved:

locking/lockdep: Fix NULL pointer dereference in __lock_set_class()

register_lock_class() can return NULL when the lock class pool is exhausted, graph_lock() fails, or key validation fails. However, __lock_set_class() uses the return value directly in pointer arithmetic without a NULL check:

class = register_lock_class(lock, subclass, 0); hlock->class_idx = class - lock_classes;

If class is NULL, this computes a wild offset that corrupts hlock->class_idx. The subsequent reacquire_held_locks() call will invoke hlock_class() with this corrupted index, leading to a NULL or out-of-bounds pointer dereference.

Add the missing NULL check, consistent with how __lock_acquire() already handles this case at the same call site.