CVE-2026-53325
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
29/06/2026
Last modified:
06/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
agp/amd64: Fix broken error propagation in agp_amd64_probe()<br />
<br />
A NULL pointer dereference was observed in the AMD64 AGP driver when<br />
running in a virtualized environment (e.g. qemu/kvm) without a physical<br />
AMD northbridge. The crash occurs in amd64_fetch_size() when attempting<br />
to dereference the pointer returned by node_to_amd_nb(0).<br />
<br />
The root cause of this crash is broken error propagation in<br />
agp_amd64_probe(): When no AMD northbridges are found, cache_nbs()<br />
correctly returns -ENODEV. However, the probe function erroneously<br />
checks the return value against exactly -1, rather than misc member.<br />
<br />
Fix the issue by correcting the error check in agp_amd64_probe() to<br />
abort properly when cache_nbs() returns any negative error code. This<br />
prevents the driver from erroneously proceeding without hardware, thereby<br />
avoiding the subsequent NULL pointer dereference at its source.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.18 (including) | 5.10.260 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.211 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.177 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.144 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.95 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.37 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.1 (including) | 7.1.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0aa9b27c454c53074cde592eaceb442d30341585
- https://git.kernel.org/stable/c/1d7d45050e14083c1de1460c93f4063c1f0bca7b
- https://git.kernel.org/stable/c/3e844a63668d1c3d10a9d347d7ebf161b2f91c84
- https://git.kernel.org/stable/c/53483a9f4ee9eeb18aa866ec16cce79e136987e1
- https://git.kernel.org/stable/c/564b3b3f6565313eb6fa5355ffd037d6fb27897f
- https://git.kernel.org/stable/c/b08472db93b1ccff84a7adec5779d47f0e9d3a30
- https://git.kernel.org/stable/c/ce800993af477fc24187349c6a20d3073140b759
- https://git.kernel.org/stable/c/cefe535a60a2e00e09f4b2689b0c8ffc6912459a
- https://git.kernel.org/stable/c/eb045714bc6a2bbb0befb7a31b996a196e188869



