CVE-2026-43122

medium Red Hat
Published: May 6, 2026 (8 days ago)
Last Modified: May 6, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Linux kernel's Advanced Configuration and Power Interface (ACPI) cpuidle driver. Due to an update in the `__acpi_processor_start()` function, a NULL pointer dereference can occur if `acpi_processor_power_init()` is called without a cpuidle driver. This vulnerability could allow a local attacker to trigger a system crash, leading to a denial of service (DoS).

CWE

CWE-476

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References