MEDIUM

CVE-2026-53042

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

fwctl: Fix class init ordering to avoid NULL pointer dereference on device removal

CXL is linked before fwctl in drivers/Makefile. Both use `module_init, so
`cxl_pci_driver_init()` runs first. When `cxl_pci_probe()` calls
`fwctl_register()` and then `device_add()`, fwctl_class is not yet
registered because fwctl_init() hasn't run, causing `class_to_subsys()` to
return NULL and skip knode_class initialization.

On device removal, `class_to_subsys()` returns non-NULL, and
`device_del()` calls `klist_del()` on the uninitialized knode, triggering
a NULL pointer dereference.

Summary dbcve.org

A kernel module initialization ordering bug causes a NULL pointer dereference when CXL devices are removed. Since CXL is linked before fwctl in the Makefile, cxl_pci_probe() calls fwctl_register() before fwctl_init() registers the fwctl_class. This leaves knode_class uninitialized. When the device is later removed, class_to_subsys() returns valid (fwctl_init has since run), causing device_del() to call klist_del() on the uninitialized knode, triggering the NULL dereference.

Mitigation

This is a kernel bug requiring a code fix to ensure proper initialization ordering between CXL and fwctl modules. Kernel update to a version containing the fix is required.

Patch Commit

Weakness (CWE)

CWE-824

EPSS Score

0.12%
Probability of exploitation in next 30 days
2.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE