PT-2026-54800 · Linux+1 · Linux Kernel+1

CVE-2026-53332

·

Published

2026-06-05

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the slimbus qcom-ngd-ctrl component where callbacks may operate on uninitialized data. This occurs when the remoteproc starts in parallel with the NGD driver being probed, when the remoteproc is already active during PDR lookup registration, or upon receiving a hardware interrupt. This condition can lead to boot failures on affected boards, exemplified by the qcom slim ngd ssr pdr notify() function attempting to schedule work on a NULL ngd up work variable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

NULL Pointer Dereference

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13868
CVE-2026-53332
ECHO-AB80-F6A4-0E40
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu