Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97484

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/09/2026
Última modificación:
24/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usbip: vhci_hcd: fix NULL deref in status_show_vhci<br /> <br /> platform_get_drvdata() can return NULL if a VHCI host controller&amp;#39;s<br /> probe failed (e.g. due to USB bus number exhaustion). status_show_vhci()<br /> checked for a NULL pdev but not for a NULL hcd returned by<br /> platform_get_drvdata(). Passing NULL to hcd_to_vhci_hcd() does not<br /> return NULL - it returns a pointer offset of 0x260, causing a NULL<br /> pointer dereference when that value is subsequently dereferenced.<br /> <br /> Add a NULL check on hcd before calling hcd_to_vhci_hcd(). Move<br /> status_show_not_ready() above status_show_vhci() to make it callable<br /> from the new error path without a forward declaration.

Impacto