CVE-2026-53042
Description
In the Linux kernel, the following vulnerability has been resolved:
fwctl: Fix class init ordering to avoid NULL pointer dereference on device removal
CXL is linked before fwctl in drivers/Makefile. Both use `module_init, so
`cxl_pci_driver_init()` runs first. When `cxl_pci_probe()` calls
`fwctl_register()` and then `device_add()`, fwctl_class is not yet
registered because fwctl_init() hasn't run, causing `class_to_subsys()` to
return NULL and skip knode_class initialization.
On device removal, `class_to_subsys()` returns non-NULL, and
`device_del()` calls `klist_del()` on the uninitialized knode, triggering
a NULL pointer dereference.
Summary dbcve.org
A kernel module initialization ordering bug causes a NULL pointer dereference when CXL devices are removed. Since CXL is linked before fwctl in the Makefile, cxl_pci_probe() calls fwctl_register() before fwctl_init() registers the fwctl_class. This leaves knode_class uninitialized. When the device is later removed, class_to_subsys() returns valid (fwctl_init has since run), causing device_del() to call klist_del() on the uninitialized knode, triggering the NULL dereference.
Mitigation
This is a kernel bug requiring a code fix to ensure proper initialization ordering between CXL and fwctl modules. Kernel update to a version containing the fix is required.