A vulnerability identified as very critical has been detected in Linux Kernel up to 6.12.100/6.18.41/7.1.4. The impacted element is the function mtd_get_fact_prot_info of the file drivers/mtd/maps/vmu-flash.c of the component vmu-flash. This manipulation causes uninitialized pointer.

This vulnerability is registered as CVE-2026-72168. The attack needs to be launched locally. No exploit is available.

You should upgrade the affected component.