NULL pointer dereference in Linux kernel - CVE-2026-64295
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in the page_ext iteration API when handling memory hotplug operations. A local user can trigger memory online operations that advance iteration past the requested page frame number range to cause a denial of service.
The issue occurs at the boundary of the last valid section when the iterator count equals the requested page count.