Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-68378

Published Aug 10, 2026 EPSS 0.20% (10th pctl)

Overview

CVE-2026-68378 is a known-severity vulnerability. It was published on August 10, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync()

When a dpll_pin is shared across multiple dpll_device instances and

those devices are being unregistered (e.g. during driver module removal),

a NULL pointer dereference can occur in dpll_msg_add_pin_ref_sync().

This happens under the following conditions:

- A pin is registered with two or more dpll devices (dpll_A, dpll_B)

- The pin has ref_sync pairs with other pins

- During unregistration of dpll_A's pins, a ref_sync partner pin is

unregistered first, removing it from dpll_A->pin_refs

- But since the partner pin is still registered with dpll_B, its

dpll_refs is not empty, so dpll_pin_ref_sync_pair_del() does NOT

run and the partner stays in the pin's ref_sync_pins xarray

- When the pin itself is then unregistered from dpll_A, the delete

notification calls dpll_msg_add_pin_ref_sync() which finds the

partner in ref_sync_pins, passe

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-68378?

CVE-2026-68378 is a known-severity vulnerability. It was published on August 10, 2026.

How severe is CVE-2026-68378?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-68378?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-68378?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-68378 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.