PT-2026-54816 · Linux+1 · Linux Kernel+1

CVE-2026-53348

·

Published

2026-07-01

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference exists in the Linux kernel within the ASoC SDCA component. The function sdca dev unregister functions() iterates through SDCA function descriptors and calls sdca dev unregister() on each func dev without verifying if the pointer is NULL. This can occur if function registration fails partially or if device cleanup races with probe deferral, resulting in a kernel oops. This issue was observed on a Lenovo ThinkPad X1 Carbon G14 (Panther Lake) when the SOF audio driver probe failed due to missing firmware, triggering a crash during the cleanup of SoundWire devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53348
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu