Answer in brief
CVE-2026-68434 records a Unknown severity vulnerability in serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6 <1096397c31f6bffa95e77bdd18fbca085be83e10 || >=977855894bca4b87afa50d21e3f3e85a5a0e901f <600dcd548fb2b00a69f447684f52ba45d5a3540e || >=1cd54e217c6e2cdb794a897b2f855e13ffcee586 <b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56 || >=9690e8a342632344984af72bc56b7a1fba61e6cb <8cbad52ccfa6a7f089cfab34979bc6cc3bff25be || >=b1b4efea05a56c0995e4702a86d6624b4fdff32f <7fb13fd7e9a59a37cd911efff83abe19e3ee029d || 763d61ded752fbb3116efc951eff4363f237b7e0 || c7d190bb07bf4e3b217c69370e94d1b4c80a40ad || 0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c || >=6.6.145 <6.6.148 || >=6.12.96 <6.12.101 || >=6.18.39 <6.18.42 || >=7.1.4 <7.1.6 || >=5.10.261 <5.11 || >=5.15.212 <5.16 || >=6.1.178 <6.2 | 1096397c31f6bffa95e77bdd18fbca085be83e10, 600dcd548fb2b00a69f447684f52ba45d5a3540e, b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56, 8cbad52ccfa6a7f089cfab34979bc6cc3bff25be, 7fb13fd7e9a59a37cd911efff83abe19e3ee029d, 6.6.148, 6.12.101, 6.18.42, 7.1.6, 5.11, 5.16, 6.2 |
| Linux/Linuxgeneric | 7.2-rc3 | Not reported |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms Commit b1b4efea05a5 ("serial: 8250_mid: Disable DMA for selected platforms") replaced the dnv_board setup and exit callbacks with PTR_IF(false, ...), which evaluates to NULL. However, the three call sites in mid8250_probe() and mid8250_remove() unconditionally dereference these function pointers without NULL checks, causing a NULL pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon D (ICX-D/CDF), or Snowridge (SNR) platform. Fix this by adding the missing NULL checks before calling the setup and exit callbacks.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68434 records a Unknown severity vulnerability in serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=587afb06a5d1dc5092d3d9e9ac3ccf22094d50c6 <1096397c31f6bffa95e77bdd18fbca085be83e10 || >=977855894bca4b87afa50d21e3f3e85a5a0e901f <600dcd548fb2b00a69f447684f52ba45d5a3540e || >=1cd54e217c6e2cdb794a897b2f855e13ffcee586 <b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56 || >=9690e8a342632344984af72bc56b7a1fba61e6cb <8cbad52ccfa6a7f089cfab34979bc6cc3bff25be || >=b1b4efea05a56c0995e4702a86d6624b4fdff32f <7fb13fd7e9a59a37cd911efff83abe19e3ee029d || 763d61ded752fbb3116efc951eff4363f237b7e0 || c7d190bb07bf4e3b217c69370e94d1b4c80a40ad || 0b3ed3fa227ba778cabed96e7f8d84addb8bdf9c || >=6.6.145 <6.6.148 || >=6.12.96 <6.12.101 || >=6.18.39 <6.18.42 || >=7.1.4 <7.1.6 || >=5.10.261 <5.11 || >=5.15.212 <5.16 || >=6.1.178 <6.2 | 1096397c31f6bffa95e77bdd18fbca085be83e10, 600dcd548fb2b00a69f447684f52ba45d5a3540e, b2a3eeb57ba24f8a0e34a69d40adcc63e5b9ca56, 8cbad52ccfa6a7f089cfab34979bc6cc3bff25be, 7fb13fd7e9a59a37cd911efff83abe19e3ee029d, 6.6.148, 6.12.101, 6.18.42, 7.1.6, 5.11, 5.16, 6.2 |
| Linux/Linuxgeneric | 7.2-rc3 | Not reported |
Published upstream
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 12, 2026
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms Commit b1b4efea05a5 ("serial: 8250_mid: Disable DMA for selected platforms") replaced the dnv_board setup and exit callbacks with PTR_IF(false, ...), which evaluates to NULL. However, the three call sites in mid8250_probe() and mid8250_remove() unconditionally dereference these function pointers without NULL checks, causing a NULL pointer dereference (kernel oops) on any Denverton (DNV), Ice Lake Xeon D (ICX-D/CDF), or Snowridge (SNR) platform. Fix this by adding the missing NULL checks before calling the setup and exit callbacks.
Quoted source text, attributed separately from HOL analysis.