CVE-2026-64368: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:49:45 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072522-CVE-2026-64368-014f@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the full object size even if a smaller size is requested, in order to provide krealloc()'s __GFP_ZERO guarantees. But if we track the requested size, krealloc() uses that information to do the right thing, so we can zero only the requested size. With red zoning also enabled, any extra size became part of the red zone, so it must not be zeroed and thus we must zero only the requested size. However the current check is imprecise, and will trigger also when only SLAB_RED_ZONE is enabled without SLAB_STORE_USER (which enables tracking the requested size). This means enabling red zoning alone can compromise krealloc()'s __GFP_ZERO contract. Fix this by using slub_debug_orig_size() instead, which is the exact check for whether the requested size is tracked. We don't need to care if red zoning is also enabled or not. Also update and expand the comment accordingly. The Linux kernel CVE team has assigned CVE-2026-64368 to this issue. Affected and fixed versions =========================== Issue introduced in 6.2 with commit 9ce67395f5a0cdec6ce152d26bfda13b98b25c01 and fixed in 6.6.145 with commit 6256899c3a34674bba6076884aedbba49fc695e4 Issue introduced in 6.2 with commit 9ce67395f5a0cdec6ce152d26bfda13b98b25c01 and fixed in 6.12.96 with commit 7e706d50fa119eead6376bf0ef973e8d73a96030 Issue introduced in 6.2 with commit 9ce67395f5a0cdec6ce152d26bfda13b98b25c01 and fixed in 6.18.39 with commit 2382971aaaef5bf85a651234c64906f59580b8be Issue introduced in 6.2 with commit 9ce67395f5a0cdec6ce152d26bfda13b98b25c01 and fixed in 7.1.4 with commit 0d18ccef142f04433dfb2a0c120cf223d2b8a42c Issue introduced in 6.2 with commit 9ce67395f5a0cdec6ce152d26bfda13b98b25c01 and fixed in 7.2-rc1 with commit 648927ceb84021a25a0fbd5673740956f318d534 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64368 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: mm/slub.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6256899c3a34674bba6076884aedbba49fc695e4 https://git.kernel.org/stable/c/7e706d50fa119eead6376bf0ef973e8d73a96030 https://git.kernel.org/stable/c/2382971aaaef5bf85a651234c64906f59580b8be https://git.kernel.org/stable/c/0d18ccef142f04433dfb2a0c120cf223d2b8a42c https://git.kernel.org/stable/c/648927ceb84021a25a0fbd5673740956f318d534