NULL pointer dereference in Linux kernel - CVE-2026-46284
Published: June 10, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in hugetlb_add_param() in mm/hugetlb.c when parsing kernel command-line parameters without an '=' separator. A local attacker can supply a crafted kernel command-line parameter to cause a denial of service.
The issue can crash the system during early boot when hugepages, hugepagesz, or default_hugepagesz are specified without a value separator.