Description
In the Linux kernel, the following vulnerability has been resolved:

dm-verity: fix a possible NULL pointer dereference

Fix a possible NULL pointer dereference dm_verity_loadpin_is_bdev_trusted
if the device has no table.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The dm‑verity module in the Linux kernel contains a flaw that can cause a NULL pointer dereference when loading a block device that lacks a device‑mapper table. This dereference would trigger a kernel OOPS and lead to a system crash, thereby denying service.

Affected Systems

The dm‑verity subsystem is part of the Linux kernel. All distributions shipping a kernel that includes dm‑verity with the fault unpatched are affected. No specific kernel release numbers appear in the data, so any kernel version prior to the commit introducing the fix is considered vulnerable. The vendor/product information indicates the entire Linux kernel is impacted.

Risk and Exploitability

The vulnerability requires the creation or loading of a block device without a device‑mapper table. Based on the description, it is inferred that an attacker would need local or privileged access to perform such operations, as no remote trigger is mentioned. The resulting kernel panic does not allow arbitrary code execution but does cause a denial of service. The CVSS score of 5.5 reflects medium severity; the EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, suggesting a low probability of real‑world exploitation.

Generated by OpenCVE AI on August 18, 2026 at 03:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install an updated Linux kernel that includes the dm‑verity null pointer dereference fix.
  • If an update cannot be applied immediately, disable dm‑verity on devices that may not have a device‑mapper table (e.g., set dm‑verity off or avoid mounting such devices).
  • Monitor kernel logs for OOPS or panic messages that may indicate the fault, and plan for system restarts when they occur.

Generated by OpenCVE AI on August 18, 2026 at 03:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix a possible NULL pointer dereference Fix a possible NULL pointer dereference dm_verity_loadpin_is_bdev_trusted if the device has no table.
Title dm-verity: fix a possible NULL pointer dereference
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:08:08.851Z

Reserved: 2026-08-09T03:40:39.905Z

Link: CVE-2026-72097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:21:23.790

Modified: 2026-08-17T06:18:08.597

Link: CVE-2026-72097

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72097 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T03:45:04Z

Weaknesses