CVE-2026-64417: mm: shrinker: fix NULL pointer dereference in debugfs
Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:50:34 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072533-CVE-2026-64417-50a1@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: mm: shrinker: fix NULL pointer dereference in debugfs shrinker_debugfs_add() creates both "count" and "scan" debugfs files unconditionally. That assumes every shrinker implements both count_objects() and scan_objects(), which is not guaranteed. For example, the xen-backend shrinker sets count_objects() but leaves scan_objects() NULL, so writing to its scan file calls through a NULL function pointer and panics the kernel: BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:0x0 Code: Unable to access opcode bytes at 0xffffffffffffffd6. Call Trace: <TASK> shrinker_debugfs_scan_write+0x12e/0x270 full_proxy_write+0x5f/0x90 vfs_write+0xde/0x420 ? filp_flush+0x75/0x90 ? filp_close+0x1d/0x30 ? do_dup2+0xb8/0x120 ksys_write+0x68/0xf0 ? filp_flush+0x75/0x90 do_syscall_64+0xb3/0x5b0 entry_SYSCALL_64_after_hwframe+0x76/0x7e The count path has the same issue in principle if a shrinker omits count_objects(). To fix it, only create "count" and "scan" debugfs files when the corresponding callbacks are present. The Linux kernel CVE team has assigned CVE-2026-64417 to this issue. Affected and fixed versions =========================== Issue introduced in 6.0 with commit bbf535fd6f06b94b9d07ed6f09397a936d4a58d8 and fixed in 6.1.178 with commit ebb45c2648b1f60715fd283700f651e05e431231 Issue introduced in 6.0 with commit bbf535fd6f06b94b9d07ed6f09397a936d4a58d8 and fixed in 6.6.145 with commit 09d2407985b8ce3e831f9d4310fe7ac06a6b3ae9 Issue introduced in 6.0 with commit bbf535fd6f06b94b9d07ed6f09397a936d4a58d8 and fixed in 6.12.96 with commit 36f8534f461222291a74156ab91f3ba9f09b6f93 Issue introduced in 6.0 with commit bbf535fd6f06b94b9d07ed6f09397a936d4a58d8 and fixed in 6.18.39 with commit 006467ab932698612398f853344a7405164541f4 Issue introduced in 6.0 with commit bbf535fd6f06b94b9d07ed6f09397a936d4a58d8 and fixed in 7.1.4 with commit b9beed2322f3538b0d2d53307062da4102b8d8d8 Issue introduced in 6.0 with commit bbf535fd6f06b94b9d07ed6f09397a936d4a58d8 and fixed in 7.2-rc3 with commit e30453c61e185e914fde83c650e268067b140218 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64417 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: mm/shrinker_debug.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/ebb45c2648b1f60715fd283700f651e05e431231 https://git.kernel.org/stable/c/09d2407985b8ce3e831f9d4310fe7ac06a6b3ae9 https://git.kernel.org/stable/c/36f8534f461222291a74156ab91f3ba9f09b6f93 https://git.kernel.org/stable/c/006467ab932698612398f853344a7405164541f4 https://git.kernel.org/stable/c/b9beed2322f3538b0d2d53307062da4102b8d8d8 https://git.kernel.org/stable/c/e30453c61e185e914fde83c650e268067b140218