CVE-2026-64052
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
30/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()<br />
<br />
pin_user_pages_fast() can partially succeed and return the number of<br />
pages that were actually pinned. However, the bio_integrity_map_user()<br />
does not handle this partial pinning. This leads to a general protection<br />
fault since bvec_from_pages() dereferences an unpinned page address,<br />
which is 0.<br />
<br />
To fix this, add a check to verify that all requested memory is pinned.<br />
If partial pinning occurs, unpin the memory and return -EFAULT.<br />
<br />
Kernel Oops:<br />
<br />
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI<br />
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]<br />
CPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy)<br />
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014<br />
RIP: 0010:bio_integrity_map_user.cold+0x1b0/0x9d6



