Description
In the Linux kernel, the following vulnerability has been resolved:

vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()

find_vm_area() can return NULL if the given address is not a valid vmalloc
area. Check the return value before dereferencing it to avoid a kernel
crash.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability causes a null pointer dereference in the function that checks for huge page usage of a vmalloc area. If a caller passes an address that is not a valid vmalloc mapping, the helper that retrieves the area may return NULL. The subsequent dereference results in a kernel crash, interrupting operating system services and potentially bringing the system down. This flaw permits an attacker to produce a denial of service by forcing the kernel to panic.

Affected Systems

The flaw is present in the Linux kernel itself; no specific kernel release numbers are listed in the data, so it could affect any version that has not applied this patch. The affected vendor is the Linux kernel project.

Risk and Exploitability

The exploit requires initiating a path that ultimately calls the vulnerable helper with an invalid address, which normally only privileged or local code can do. The vulnerability is not listed in CISA’s KEV database, and its EPSS score is < 1 %, indicating a very low probability of exploitation in the wild. The CVSS score of 5.5 reflects a medium severity denial‑of‑service impact, as a kernel crash will interrupt operating system services. No remote exploitation path is documented; the attack remains effectively local.

Generated by OpenCVE AI on August 22, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the commit fixing this null pointer dereference; refer to the vendor’s update channel or the commit list for the earliest patched version.
  • If an immediate kernel upgrade is not possible, limit the execution of code paths that perform vmalloc area lookups with arbitrary addresses—for example, by running untrusted workloads under strong containment such as containers or by enforcing capability restrictions on privileged processes.
  • Continuously monitor system logs for signs of kernel panics and apply the update as soon as it becomes available to eliminate the crash vector.

Generated by OpenCVE AI on August 22, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Sat, 15 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() find_vm_area() can return NULL if the given address is not a valid vmalloc area. Check the return value before dereferencing it to avoid a kernel crash.
Title vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:17:17.979Z

Reserved: 2026-08-15T05:44:03.884Z

Link: CVE-2026-74327

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:33.383

Modified: 2026-08-17T06:19:27.117

Link: CVE-2026-74327

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74327 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T00:15:05Z

Weaknesses