Linux Kernel Legacy NCM Driver NULL Pointer Dereference Vulnerability

Vulnerability

A NULL pointer dereference vulnerability has been identified in the legacy NCM driver of the Linux kernel. This issue arises from a change in the net_device lifecycle management, which deferred the allocation of the net_device. As a result, the driver attempts to access the net_device before it is fully initialized, leading to a crash. The vulnerability affects the Linux kernel stable tree.

Impact

Exploitation of this vulnerability causes a NULL pointer dereference, leading to a crash of the affected component.

Remediation

The vulnerability has been addressed in the official Linux Git repository. Users can upgrade to the latest version of the Linux kernel to apply the fix.

Added: May 8, 2026, 8:38 PM
Updated: May 8, 2026, 8:38 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
3.5
remediation
7.7
relevance
7.8
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.