news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-53048

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.5 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.12%
Risk score
1.3
Published
2026-06-24
Status
Published

In the Linux kernel, the following vulnerability has been resolved: gfs2: prevent NULL pointer dereference during unmount When flushing out outstanding glock work during an unmount, gfs2_log_flush() can be called when sdp->sd_jdesc has already been deallocated and sdp->sd_jdesc is NULL. Commit 35264909e9d1 ("gfs2: Fix NULL pointer dereference in gfs2_log_flush") added a check for that to gfs2_log_flush() itself, but it missed the sdp->sd_jdesc dereference in gfs2_log_release(). Fix that. A flaw was found in the Linux kernel's gfs2 filesystem. During the unmount process, a NULL pointer dereference can occur when flushing outstanding glock work. This happens because `gfs2_log_flush()` is called when a critical data structure (`sdp->sd_jdesc`) has already been deallocated, and a subsequent dereference in `gfs2_log_release()` lacks a necessary NULL check. An attacker could potentially exploit this to cause a system crash, leading to a Denial of Service (DoS).

Weaknesses

CWE-825

Coverage 5

Advisories and references