CVE-2026-64297 | Linux Kernel up to 7.1.3 decompress module_extend_max_pages Info null pointer dereference

SecurityVulns

A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3. Impacted is the function module_extend_max_pages of the component decompress. Performing a manipulation of the argument Info results in null pointer dereference.

This vulnerability is identified as CVE-2026-64297. The attack is only possible with local access. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More