GHSA-mh76-8wxp-345hunknown

In the Linux kernel, the following vulnerability has been resolved: locking/lockdep: Fix NULL...

Published
September 24, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

locking/lockdep: Fix NULL pointer dereference in __lock_set_class()

register_lock_class() can return NULL when the lock class pool is exhausted, graph_lock() fails, or key validation fails. However, __lock_set_class() uses the return value directly in pointer arithmetic without a NULL check:

class = register_lock_class(lock, subclass, 0); hlock->class_idx = class - lock_classes;

If class is NULL, this computes a wild offset that corrupts hlock->class_idx. The subsequent reacquire_held_locks() call will invoke hlock_class() with this corrupted index, leading to a NULL or out-of-bounds pointer dereference.

Add the missing NULL check, consistent with how __lock_acquire() already handles this case at the same call site.

🔗 References (10)