CVE-2026-53048: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: gfs2: prevent NULL pointer dereference during unmount When flushing out outstanding glock work during an unmount, gfs2_log_flush() can be called when sdp->sd_jdesc has already been deallocated and sdp->sd_jdesc is NULL. Commit 35264909e9d1 ("gfs2: Fix NULL pointer dereference in gfs2_log_flush") added a check for that to gfs2_log_flush() itself, but it missed the sdp->sd_jdesc dereference in gfs2_log_release(). Fix that.

Affected products

  • Linux Linux Kernel: from 5.15.200, before 5.15.209 (fixed in 5.15.209); from 6.1.162, before 6.1.175 (fixed in 6.1.175); from 6.6.37, before 6.6.141 (fixed in 6.6.141); from 6.9.8, before 6.12.91 (fixed in 6.12.91); from 6.13, before 6.18.33 (fixed in 6.18.33); from 6.19, before 7.0.10 (fixed in 7.0.10)

Published 2026-06-24. Last modified 2026-07-21.