CVE-2026-64297 Details
Description
In the Linux kernel, the following vulnerability has been resolved: module: decompress: check return value of module_extend_max_pages() module_extend_max_pages() calls kvrealloc() internally and returns -ENOMEM on allocation failure. The return value is never checked. If the initial allocation fails, info->pages remains NULL and info->max_pages remains 0. Subsequent calls to module_get_next_page() will attempt to dynamically grow the array by calling module_extend_max_pages(info, 0) since info->used_pages is 0. This results in kvrealloc(NULL, 0) returning ZERO_SIZE_PTR, which is treated as a success, leading to a dereference of ZERO_SIZE_PTR and a kernel oops. Fix: add the missing error check after module_extend_max_pages() and return immediately on failure. This matches the pattern used by every other kvrealloc() caller in the module loading path. [Sami: Corrected the analysis in the commit message.]
A vulnerability in the Linux kernel's module decompression process can lead to a zero-size pointer dereference, causing a kernel oops. This issue arises because the return value of the 'module_extend_max_pages()' function, which handles memory allocation, is not properly checked. When the allocation fails, the module's page information remains uninitialized. Subsequent attempts to access and expand this information inadvertently create a situation where a null pointer is treated as valid, leading to a crash.
The vulnerability has been addressed by adding the missing error check after the 'module_extend_max_pages()' call. Users should update to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/168072baf9ad516d5a06046514c7fea4c0671990 | kernel.org | Patch |
| https://git.kernel.org/stable/c/786d2d84416a9a1c1a47b71a68d679d886284be2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/a82e170637e050a803b4f37542371ef216bf66d2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/afcc0515bbdd28d509a2b5870faaa89b137f5d53 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e7da02659c229f73492fb1ed87ceda4090153aaa | kernel.org | Patch |
| https://git.kernel.org/stable/c/e7f174715f9f0cbcb9e87b52e4fc4ef149baac98 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.17, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | kernel.org |
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Jul 25, 2026 | New CVE Received | kernel.org |