Junglewise Threat Intelligence

CVE-2026-64416: Linux Kernel NULL pointer dereference in lookup_swap_cgroup_id

CVE-2026-64416 · Severity: info · CVSS 6.2 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory management system can cause a complete system crash (kernel panic). This occurs on systems that do not use swap space when certain internal memory records become corrupted. While the corruption itself is caused by a separate issue, this flaw allows that corruption to trigger a system-wide failure during normal process termination, potentially leading to data loss or service outages.

Technical details

A NULL pointer dereference exists in mm/swap_cgroup.c within the lookup_swap_cgroup_id() function. The vulnerability is triggered when zap_pte_range() calls swap_pte_batch(), which invokes lookup_swap_cgroup_id() on a Page Table Entry (PTE) that appears to be a swap entry without prior validation against swap_info[]. On hosts without swap enabled, the cgroup control map is NULL, leading to a dereference of NULL plus a scaled offset. This results in a kernel oops/panic during exit_mmap or do_exit. The issue was introduced by the batching of swap entry freeing in commit bea67dcc5eea. Patches have been released for various stable kernel branches including 6.12.x.

Affected products

  • Linux Linux Kernel 6.12.58

Timeline

  • 2026-05-04: disclosed: Initial patch submission by Jose Fernandez (Anthropic)
  • 2026-07-25: advisory: CVE-2026-64416 published

References

Related threats