Home

Description

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix early boot crash on parameters without '=' separator If hugepages, hugepagesz, or default_hugepagesz are specified on the kernel command line without the '=' separator, early parameter parsing passes NULL to hugetlb_add_param(), which dereferences it in strlen() and can crash the system during early boot. Reject NULL values in hugetlb_add_param() and return -EINVAL instead.

PUBLISHED Reserved 2026-05-13 | Published 2026-06-08 | Updated 2026-06-08 | Assigner Linux

Product status

Default status
unaffected

5b47c02967ab770aa7661c8863a21b2fd59e35ff (git) before 2774bcf714739cc6bb86f8812167bb9fbda70f6a
affected

5b47c02967ab770aa7661c8863a21b2fd59e35ff (git) before 357c6d084b6137ae640209c5bfd01180f985c015
affected

5b47c02967ab770aa7661c8863a21b2fd59e35ff (git) before c45b354911d01565156e38d7f6bc07edb51fc34c
affected

Default status
affected

6.15
affected

Any version before 6.15
unaffected

6.18.27 (semver)
unaffected

7.0.4 (semver)
unaffected

7.1-rc1 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/2774bcf714739cc6bb86f8812167bb9fbda70f6a

git.kernel.org/...c/357c6d084b6137ae640209c5bfd01180f985c015

git.kernel.org/...c/c45b354911d01565156e38d7f6bc07edb51fc34c

cve.org (CVE-2026-46284)

nvd.nist.gov (CVE-2026-46284)

Download JSON