CVE-2026-68176

Source
https://cve.org/CVERecord?id=CVE-2026-68176
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68176.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68176
Downstream
Published
2026-08-10T11:59:47.298Z
Modified
2026-08-12T04:18:46.203669136Z
Summary
tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev
Details

In the Linux kernel, the following vulnerability has been resolved:

tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev

If the mmiopipeopen() fails to find a PCI device, the hiter->dev will be assigned to NULL. The mmiotrace read() function dereferences the hiter->dev if hiter exists.

Change the test of the read to not only check hiter being NULL, but also the hiter->dev before dereferencing it.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68176.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f984b51e0779a6dd30feedc41404013ca54e5d05
Fixed
faaf95135184208ee3ac6f33175c8d1800669dfc
Fixed
201a01102c529772168181190cb084471082cf5c
Fixed
8464427e1c177809a9488a97dfa2807d9dcf323b
Fixed
724cd84b0546c07806840fa658714488553d13a2
Fixed
144f29e85702234b23d2a62abf723e6a17eb5427

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68176.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.27
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68176.json"