๐Ÿ” CVE Alert

CVE-2026-53158

UNKNOWN 0.0

misc: fastrpc: Fix NULL pointer dereference in rpmsg callback

CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
6th

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix NULL pointer dereference in rpmsg callback A NULL pointer dereference was observed on Hawi at boot when the DSP sends a glink message before fastrpc_rpmsg_probe() has completed initialization: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000178 pc : _raw_spin_lock_irqsave+0x34/0x8c lr : fastrpc_rpmsg_callback+0x3c/0xcc [fastrpc] ... Call trace: _raw_spin_lock_irqsave+0x34/0x8c (P) fastrpc_rpmsg_callback+0x3c/0xcc [fastrpc] qcom_glink_native_rx+0x538/0x6a4 qcom_glink_smem_intr+0x14/0x24 [qcom_glink_smem] The faulting address 0x178 corresponds to the lock variable inside struct fastrpc_channel_ctx, confirming that cctx is NULL when fastrpc_rpmsg_callback() attempts to take the spinlock. There are two issues here. First, dev_set_drvdata() is called before spin_lock_init() and idr_init(), leaving a window where the callback can retrieve a valid cctx pointer but operate on an uninitialized spinlock. Second, the rpmsg channel becomes live as soon as the driver is bound, so fastrpc_rpmsg_callback() can fire before dev_set_drvdata() is called at all, resulting in dev_get_drvdata() returning NULL. Fix both issues by moving all cctx initialization ahead of dev_set_drvdata() so the structure is fully initialized before it becomes visible to the callback, and add a NULL check in fastrpc_rpmsg_callback() as a guard against any remaining window.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jun 25, 2026
Last Updated Jul 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < a3d91218ccca1e990bfb737b5a6da23f0afba22b f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < 0d8c64511fd45690c5326f013710efcb4f73a97e f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < 150bf6f1193c69252580c19d3b3cd631ddce61d7 f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < 8fb4a23df5b7c02929b62e5dbc270ec7c42b8134 f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < 4bfdf0a9855df55e9e031ca6a25b855820590c70 f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < d5de9cb5355db36438edc621dde3673e3f235767 f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < d77583ca33299fede0c194744ef2284e7ba5b763 f6f9279f2bf0e37e2f1fb119d8832b8568536a04 < 5401fb4fe10fac6134c308495df18ed74aebb9c4
Linux / Linux
5.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a3d91218ccca1e990bfb737b5a6da23f0afba22b git.kernel.org: https://git.kernel.org/stable/c/0d8c64511fd45690c5326f013710efcb4f73a97e git.kernel.org: https://git.kernel.org/stable/c/150bf6f1193c69252580c19d3b3cd631ddce61d7 git.kernel.org: https://git.kernel.org/stable/c/8fb4a23df5b7c02929b62e5dbc270ec7c42b8134 git.kernel.org: https://git.kernel.org/stable/c/4bfdf0a9855df55e9e031ca6a25b855820590c70 git.kernel.org: https://git.kernel.org/stable/c/d5de9cb5355db36438edc621dde3673e3f235767 git.kernel.org: https://git.kernel.org/stable/c/d77583ca33299fede0c194744ef2284e7ba5b763 git.kernel.org: https://git.kernel.org/stable/c/5401fb4fe10fac6134c308495df18ed74aebb9c4