CVE-2026-64297 PUBLISHED

module: decompress: check return value of module_extend_max_pages()

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

module: decompress: check return value of module_extend_max_pages()

module_extend_max_pages() calls kvrealloc() internally and returns -ENOMEM on allocation failure. The return value is never checked.

If the initial allocation fails, info->pages remains NULL and info->max_pages remains 0. Subsequent calls to module_get_next_page() will attempt to dynamically grow the array by calling module_extend_max_pages(info, 0) since info->used_pages is 0. This results in kvrealloc(NULL, 0) returning ZERO_SIZE_PTR, which is treated as a success, leading to a dereference of ZERO_SIZE_PTR and a kernel oops.

Fix: add the missing error check after module_extend_max_pages() and return immediately on failure. This matches the pattern used by every other kvrealloc() caller in the module loading path.

[Sami: Corrected the analysis in the commit message.]

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 to e7f174715f9f0cbcb9e87b52e4fc4ef149baac98 (excl.)
  • affected from b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 to afcc0515bbdd28d509a2b5870faaa89b137f5d53 (excl.)
  • affected from b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 to 168072baf9ad516d5a06046514c7fea4c0671990 (excl.)
  • affected from b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 to a82e170637e050a803b4f37542371ef216bf66d2 (excl.)
  • affected from b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 to e7da02659c229f73492fb1ed87ceda4090153aaa (excl.)
  • affected from b1ae6dc41eaaa98bb75671e0f3665bfda248c3e7 to 786d2d84416a9a1c1a47b71a68d679d886284be2 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.17 is affected
  • unaffected from 0 to 5.17 (excl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References