Description
In the Linux kernel, the following vulnerability has been resolved:

powerpc/kexec_file: Fix null-ptr-def in extra size calculation

A static Sashiko AI review identified a potential NULL pointer
dereference in kexec_extra_fdt_size_ppc64().

On platforms without any reserved memory regions,
get_reserved_memory_ranges() can return 0 while leaving 'rmem'
unallocated as NULL. Passing it directly leads to a kernel panic when
evaluating 'rmem->nr_ranges'.

Add a NULL check for 'rmem' to prevent this crash.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

The flaw is a NULL pointer dereference in the Linux kernel's powerpc/kexec_file component, specifically in the kexec_extra_fdt_size_ppc64 function. When no reserved memory regions exist, get_reserved_memory_ranges can return 0 and leave rmem unallocated, causing a kernel panic when rmem->nr_ranges is accessed. This results in a denial‑of‑service condition, as the kernel crashes.

Affected Systems

Affected systems are all Linux distributions running the Linux kernel that have not yet updated to the version containing the null‑check. The exact version ranges are not enumerated in the advisory, so any kernel prior to the patch that includes the unguarded rmem access is potentially vulnerable. All architectures using the powerpc/kexec_file code path are at risk.

Risk and Exploitability

The vulnerability requires privileged access to invoke kexec or to configure memory ranges; it is not a remote code execution vector. The EPSS score of <1% indicates low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The impact is limited to a local denial of service via a kernel panic, so the overall risk is moderate but mitigated by the low exploitation probability.

Generated by OpenCVE AI on September 18, 2026 at 04:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the null‑check for rmem in kexec_extra_fdt_size_ppc64.
  • If an upgrade is not immediately possible, restrict the use of kexec or ensure that reserved memory regions are configured so get_reserved_memory_ranges does not return zero.
  • Consider disabling kexec functionality on systems where it is unnecessary or limiting its execution to highly privileged users.

Generated by OpenCVE AI on September 18, 2026 at 04:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Fix null-ptr-def in extra size calculation A static Sashiko AI review identified a potential NULL pointer dereference in kexec_extra_fdt_size_ppc64(). On platforms without any reserved memory regions, get_reserved_memory_ranges() can return 0 while leaving 'rmem' unallocated as NULL. Passing it directly leads to a kernel panic when evaluating 'rmem->nr_ranges'. Add a NULL check for 'rmem' to prevent this crash.
Title powerpc/kexec_file: Fix null-ptr-def in extra size calculation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:45.336Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:06.807

Modified: 2026-09-16T11:17:06.807

Link: CVE-2026-89963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:15:03Z

Weaknesses