CVE-2026-80621

Updated on 28 Aug 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability

dwc_pcie_rasdes_debugfs_init() returns success when the controller has no RAS DES capability, leaving pci->debugfs->rasdes_info unset. The common debugfs teardown path still calls dwc_pcie_rasdes_debugfs_deinit(), which dereferences rasdes_info unconditionally.

Return early when no RAS DES state was allocated. In that case no RAS DES mutex was initialized, so there is nothing to destroy.

[mani: reworded subject]

Details

Affected product:
Debian 10 ELS
Affected packages:
linux @ 4.19.0

Fixes