NULL pointer dereference in Linux kernel - CVE-2026-64295

 

NULL pointer dereference in Linux kernel - CVE-2026-64295

Published: July 27, 2026


Vulnerability identifier: #VU139681
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64295
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in the page_ext iteration API when handling memory hotplug operations. A local user can trigger memory online operations that advance iteration past the requested page frame number range to cause a denial of service.

The issue occurs at the boundary of the last valid section when the iterator count equals the requested page count.


Affected software

Linux kernel

How to mitigate CVE-2026-64295

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins