Description
In the Linux kernel, the following vulnerability has been resolved:

params: fix charp corruption on allocation failure

param_set_charp() stores charp parameters in allocated memory after slab is
available, and releases the previous value when the parameter is updated.

The previous value is released before the replacement allocation succeeds.
If kmalloc_parameter() fails, the setter returns -ENOMEM with the parameter
left as NULL.

Failing zswap's compressor update before zswap is initialized can later
trigger:

BUG: kernel NULL pointer dereference, address: 0000000000000000
RIP: 0010:strcmp+0x10/0x30
Call Trace:
zswap_setup+0x3b1/0x490
zswap_enabled_param_set+0x5b/0xa0
param_attr_store+0x93/0xe0
module_attr_store+0x1c/0x30
kernfs_fop_write_iter+0x116/0x1f0

Allocate and copy the replacement first, then replace the parameter value
only after allocation succeeds.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Null pointer dereference leading to a kernel crash, causing a denial of service.
Action: Apply Patch
AI Analysis

Impact

The kernel’s parameter handling bug occurs when an attempt to update a character string parameter fails due to a memory allocation failure. The setter releases the previous parameter value before verifying that the new allocation succeeds, leaving the parameter as NULL if kmalloc_parameter() fails. Subsequent use of this NULL value, such as during a zswap compressor update, dereferences the NULL pointer and triggers a BUG and a kernel panic. This is a classic NULL pointer dereference that results in a system crash and denial of service.

Affected Systems

All Linux kernel releases that have not yet incorporated the patch are affected. The vulnerability is present in the kernel’s generic parameter handling code and manifests most prominently when the zswap module is initialized. No specific version range is listed, so all standard Linux kernels prior to the patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 4.1 classifies the vulnerability as low severity. The EPSS score indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector is local privileged or kernel‑module configuration activity that could trigger the allocation failure path, leading to a kernel crash and system downtime.

Generated by OpenCVE AI on September 15, 2026 at 21:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that contains the fix for the allocation failure bug.
  • Monitor system logs for kernel BUG messages indicating NULL pointer dereferences during zswap operations.
  • Consider disabling zswap or reducing its maximum swap usage to lessen the risk during low memory conditions.

Generated by OpenCVE AI on September 15, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: params: fix charp corruption on allocation failure param_set_charp() stores charp parameters in allocated memory after slab is available, and releases the previous value when the parameter is updated. The previous value is released before the replacement allocation succeeds. If kmalloc_parameter() fails, the setter returns -ENOMEM with the parameter left as NULL. Failing zswap's compressor update before zswap is initialized can later trigger: BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: 0010:strcmp+0x10/0x30 Call Trace: zswap_setup+0x3b1/0x490 zswap_enabled_param_set+0x5b/0xa0 param_attr_store+0x93/0xe0 module_attr_store+0x1c/0x30 kernfs_fop_write_iter+0x116/0x1f0 Allocate and copy the replacement first, then replace the parameter value only after allocation succeeds.
Title params: fix charp corruption on allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:26.091Z

Reserved: 2026-09-11T19:38:34.723Z

Link: CVE-2026-89552

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:38.760

Modified: 2026-09-11T20:19:38.760

Link: CVE-2026-89552

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:26Z

Links: CVE-2026-89552 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses