module: decompress: check return value of module_extend_max_pages()
Summary
| CVE | CVE-2026-64297 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-25 10:17:10 UTC |
| Updated | 2026-07-30 15:00:27 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: module: decompress: check return value of module_extend_max_pages() module_extend_max_pages() calls kvrealloc() internally and returns -ENOMEM on allocation failure. The return value is never checked. If the initial allocation fails, info->pages remains NULL and info->max_pages remains 0. Subsequent calls to module_get_next_page() will attempt to dynamically grow the array by calling module_extend_max_pages(info, 0) since info->used_pages is 0. This results in kvrealloc(NULL, 0) returning ZERO_SIZE_PTR, which is treated as a success, leading to a dereference of ZERO_SIZE_PTR and a kernel oops. Fix: add the missing error check after module_extend_max_pages() and return immediately on failure. This matches the pattern used by every other kvrealloc() caller in the module loading path. [Sami: Corrected the analysis in the commit message.] |
Risk And Classification
EPSS: 0.002060000 probability, percentile 0.107920000 (date 2026-08-02)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 e7f174715f9f0cbcb9e87b52e4fc4ef149baac98 git | Not specified |
| CNA | Linux | Linux | affected b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 afcc0515bbdd28d509a2b5870faaa89b137f5d53 git | Not specified |
| CNA | Linux | Linux | affected b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 168072baf9ad516d5a06046514c7fea4c0671990 git | Not specified |
| CNA | Linux | Linux | affected b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 a82e170637e050a803b4f37542371ef216bf66d2 git | Not specified |
| CNA | Linux | Linux | affected b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 e7da02659c229f73492fb1ed87ceda4090153aaa git | Not specified |
| CNA | Linux | Linux | affected b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 786d2d84416a9a1c1a47b71a68d679d886284be2 git | Not specified |
| CNA | Linux | Linux | affected 5.17 | Not specified |
| CNA | Linux | Linux | unaffected 5.17 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.96 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.39 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.4 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/786d2d84416a9a1c1a47b71a68d679d886284be2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/afcc0515bbdd28d509a2b5870faaa89b137f5d53 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a82e170637e050a803b4f37542371ef216bf66d2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e7da02659c229f73492fb1ed87ceda4090153aaa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/168072baf9ad516d5a06046514c7fea4c0671990 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e7f174715f9f0cbcb9e87b52e4fc4ef149baac98 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.