In the Linux kernel, the following vulnerability has been resolved:
fwctl: Fix class init ordering to avoid NULL pointer dereference on device removal
CXL is linked before fwctl in drivers/Makefile. Both use module_init, so
cxlpcidriverinit()runs first. Whencxlpciprobe()calls
fwctlregister()and thendeviceadd(), fwctl_class is not yet
registered because fwctl_init() hasn't run, causingclasstosubsys()` to
return NULL and skip knodeclass initialization.
On device removal, class_to_subsys() returns non-NULL, and
device_del() calls klist_del() on the uninitialized knode, triggering
a NULL pointer dereference.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53042.json",
"cna_assigner": "Linux"
}