CVE-2026-64052

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
30/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()<br /> <br /> pin_user_pages_fast() can partially succeed and return the number of<br /> pages that were actually pinned. However, the bio_integrity_map_user()<br /> does not handle this partial pinning. This leads to a general protection<br /> fault since bvec_from_pages() dereferences an unpinned page address,<br /> which is 0.<br /> <br /> To fix this, add a check to verify that all requested memory is pinned.<br /> If partial pinning occurs, unpin the memory and return -EFAULT.<br /> <br /> Kernel Oops:<br /> <br /> Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI<br /> KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]<br /> CPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy)<br /> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014<br /> RIP: 0010:bio_integrity_map_user.cold+0x1b0/0x9d6

Impact