Executive brief
A vulnerability in the Linux kernel's memory management system could cause a system crash during 'hotplug' events, which is when memory is dynamically added to a running server. This occurs because the system fails to properly check memory boundaries when updating its internal tracking records. While this primarily affects system stability and availability, it could disrupt critical operations or lead to a denial-of-service condition during hardware maintenance or scaling.
Technical details
A NULL pointer dereference exists in the Linux kernel's page_ext iteration API. The root cause is that page_ext_iter_next() does not validate if a Page Frame Number (PFN) belongs to a valid initialized section before advancing the iterator. During memory hotplug (online) operations, the for_each_page_ext() macro can increment the iterator past the current valid range (__pgcount), leading to a call to page_ext_lookup() on an uninitialized memory section. This results in a kernel panic. The fix moves boundary enforcement inside the iterator functions to prevent out-of-bounds access.
Affected products
- Linux Linux Kernel 6.15, versions before 6.15 starting from 9039b9096ea27a20f0349d1537537663c935c8ed
Timeline
- 2026-06-23: disclosed: Initial patch submission by Ketan Kishore
- 2026-07-18: patched: Commits applied to stable trees by Greg Kroah-Hartman
- 2026-07-25: advisory: CVE-2026-64295 published