CVE-2026-64368 Details
Description
In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the full object size even if a smaller size is requested, in order to provide krealloc()'s __GFP_ZERO guarantees. But if we track the requested size, krealloc() uses that information to do the right thing, so we can zero only the requested size. With red zoning also enabled, any extra size became part of the red zone, so it must not be zeroed and thus we must zero only the requested size. However the current check is imprecise, and will trigger also when only SLAB_RED_ZONE is enabled without SLAB_STORE_USER (which enables tracking the requested size). This means enabling red zoning alone can compromise krealloc()'s __GFP_ZERO contract. Fix this by using slub_debug_orig_size() instead, which is the exact check for whether the requested size is tracked. We don't need to care if red zoning is also enabled or not. Also update and expand the comment accordingly.
A vulnerability has been identified in the Linux kernel's memory allocation functions, specifically within the kmalloc() implementation. This issue arises when red zoning is enabled, which can interfere with the expected behavior of the krealloc() function that relies on the __GFP_ZERO flag to ensure proper memory initialization. The vulnerability occurs because the current mechanism for managing memory initialization does not accurately account for the red zone, potentially leading to unintended consequences when reallocating memory. The problem is particularly pronounced when only the SLAB_RED_ZONE option is active, without the SLAB_STORE_USER flag, which is essential for tracking the requested size of memory allocations. As a result, the red zone can inadvertently include uninitialized memory, compromising the integrity of memory management operations.
Users can upgrade to the latest stable version of the Linux kernel, where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0d18ccef142f04433dfb2a0c120cf223d2b8a42c | kernel.org | Patch |
| https://git.kernel.org/stable/c/2382971aaaef5bf85a651234c64906f59580b8be | kernel.org | Patch |
| https://git.kernel.org/stable/c/6256899c3a34674bba6076884aedbba49fc695e4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/648927ceb84021a25a0fbd5673740956f318d534 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7e706d50fa119eead6376bf0ef973e8d73a96030 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |