CVE-2026-46284

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix early boot crash on parameters without '=' separator If hugepages, hugepagesz, or default_hugepagesz are specified on the kernel command line without the '=' separator, early parameter parsing passes NULL to hugetlb_add_param(), which dereferences it in strlen() and can crash the system during early boot. Reject NULL values in hugetlb_add_param() and return -EINVAL instead.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: mm/hugetlb: corrige un fallo de arranque temprano en parámetros sin el separador '=' Si hugepages, hugepagesz o default_hugepagesz se especifican en la línea de comandos del kernel sin el separador '=', el análisis temprano de parámetros pasa NULL a hugetlb_add_param(), lo que lo desreferencia en strlen() y puede provocar un fallo del sistema durante el arranque temprano. Rechazar valores NULL en hugetlb_add_param() y devolver -EINVAL en su lugar.

08 Jul 2026, 21:23

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/2774bcf714739cc6bb86f8812167bb9fbda70f6a - () https://git.kernel.org/stable/c/2774bcf714739cc6bb86f8812167bb9fbda70f6a - Patch
References () https://git.kernel.org/stable/c/357c6d084b6137ae640209c5bfd01180f985c015 - () https://git.kernel.org/stable/c/357c6d084b6137ae640209c5bfd01180f985c015 - Patch
References () https://git.kernel.org/stable/c/c45b354911d01565156e38d7f6bc07edb51fc34c - () https://git.kernel.org/stable/c/c45b354911d01565156e38d7f6bc07edb51fc34c - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

08 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 17:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46284

Mitre link : CVE-2026-46284

CVE.ORG link : CVE-2026-46284


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference