CVE-2026-64297

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
25/07/2026
Last modified:
17/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> module: decompress: check return value of module_extend_max_pages()<br /> <br /> module_extend_max_pages() calls kvrealloc() internally and returns<br /> -ENOMEM on allocation failure. The return value is never checked.<br /> <br /> If the initial allocation fails, info-&gt;pages remains NULL and<br /> info-&gt;max_pages remains 0. Subsequent calls to module_get_next_page()<br /> will attempt to dynamically grow the array by calling<br /> module_extend_max_pages(info, 0) since info-&gt;used_pages is 0. This<br /> results in kvrealloc(NULL, 0) returning ZERO_SIZE_PTR, which is treated<br /> as a success, leading to a dereference of ZERO_SIZE_PTR and a kernel<br /> oops.<br /> <br /> Fix: add the missing error check after module_extend_max_pages() and<br /> return immediately on failure. This matches the pattern used by every<br /> other kvrealloc() caller in the module loading path.<br /> <br /> [Sami: Corrected the analysis in the commit message.]

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.17 (including) 6.1.178 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.145 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.96 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.39 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.1.4 (excluding)