-

CVE-2026-64417

mm: shrinker: fix NULL pointer dereference in debugfs

In the Linux kernel, the following vulnerability has been resolved:

mm: shrinker: fix NULL pointer dereference in debugfs

shrinker_debugfs_add() creates both "count" and "scan" debugfs files
unconditionally.

That assumes every shrinker implements both count_objects() and
scan_objects(), which is not guaranteed.  For example, the xen-backend
shrinker sets count_objects() but leaves scan_objects() NULL, so writing
to its scan file calls through a NULL function pointer and panics the
kernel:

BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:0x0
Code: Unable to access opcode bytes at 0xffffffffffffffd6.
Call Trace:
 <TASK>
 shrinker_debugfs_scan_write+0x12e/0x270
 full_proxy_write+0x5f/0x90
 vfs_write+0xde/0x420
 ? filp_flush+0x75/0x90
 ? filp_close+0x1d/0x30
 ? do_dup2+0xb8/0x120
 ksys_write+0x68/0xf0
 ? filp_flush+0x75/0x90
 do_syscall_64+0xb3/0x5b0
 entry_SYSCALL_64_after_hwframe+0x76/0x7e

The count path has the same issue in principle if a shrinker omits
count_objects().

To fix it, only create "count" and "scan" debugfs files when the
corresponding callbacks are present.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version bbf535fd6f06b94b9d07ed6f09397a936d4a58d8
Version < ebb45c2648b1f60715fd283700f651e05e431231
Status affected
Version bbf535fd6f06b94b9d07ed6f09397a936d4a58d8
Version < 09d2407985b8ce3e831f9d4310fe7ac06a6b3ae9
Status affected
Version bbf535fd6f06b94b9d07ed6f09397a936d4a58d8
Version < 36f8534f461222291a74156ab91f3ba9f09b6f93
Status affected
Version bbf535fd6f06b94b9d07ed6f09397a936d4a58d8
Version < 006467ab932698612398f853344a7405164541f4
Status affected
Version bbf535fd6f06b94b9d07ed6f09397a936d4a58d8
Version < b9beed2322f3538b0d2d53307062da4102b8d8d8
Status affected
Version bbf535fd6f06b94b9d07ed6f09397a936d4a58d8
Version < e30453c61e185e914fde83c650e268067b140218
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.069
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ebb45c2648b1f60715fd283700f651e05e431231
https://git.kernel.org/stable/c/09d2407985b8ce3e831f9d4310fe7ac06a6b3ae9
https://git.kernel.org/stable/c/36f8534f461222291a74156ab91f3ba9f09b6f93
https://git.kernel.org/stable/c/006467ab932698612398f853344a7405164541f4
https://git.kernel.org/stable/c/b9beed2322f3538b0d2d53307062da4102b8d8d8
https://git.kernel.org/stable/c/e30453c61e185e914fde83c650e268067b140218