Improper handling of exceptional conditions in Linux kernel - CVE-2026-64369

 

Improper handling of exceptional conditions in Linux kernel - CVE-2026-64369

Published: July 27, 2026


Vulnerability identifier: #VU139604
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64369
CWE-ID: CWE-755
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper exception handling in load_unaligned_zeropad() and the s390 secure storage access exception handler when reading unaligned data across page boundaries involving donated secure-execution pages. A local user can trigger the vulnerable kernel access pattern to cause a denial of service.

The issue can result in an endless exception loop when the second page access raises an exception for pages donated to the Ultravisor for secure execution purposes.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-64369

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.100-1

External References

Related Security Bulletins