Description
In the Linux kernel, the following vulnerability has been resolved:

mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug

We miss a failed allocation check for pgdat->per_cpu_nodestats, which
results in a NULL deref when we offset into the per-cpu area.

Propagate -ENOMEM up the stack and leave per_cpu_nodestats pointing
at boot_nodestats so a later online can retry the allocation.

hotadd_init_pgdat() returns NULL on failure, which __try_online_node()
already maps to -ENOMEM.

On failure nothing needs to be unwound:
- the node is never marked online
- per_cpu_nodestats is left pointing at boot_nodestats
- __add_memory_resource() cleans up pending memblock resources
- later online attempts retry the per_cpu_nodestats allocation
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Patch
AI Analysis

Impact

The kernel missing a check for a failed per‑CPU area allocation causes a null pointer dereference when the code offsets into the per‑CPU area. This results in an oops that can crash the operating system, providing a denial‑of‑service vector. The weakness is an unchecked null pointer dereference (CWE‑476).

Affected Systems

All versions of the Linux kernel that lack the patch addressing the crash when allocating per‑CPU memory during hot‑plug node addition are affected. The exact version range is not specified in the data; any kernel that includes the mm/mm_init code without the described fix is vulnerable.

Risk and Exploitability

The vulnerability is a null pointer dereference (CWE‑476). An attacker can trigger the defect by attempting to hot‑plug memory or otherwise force the kernel to allocate per‑CPU node statistics, which will fail and cause a crash. The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog, but the impact of a kernel crash provides a denial‑of‑service vector. The attack vector is likely local, but could be escalated via compromised kernel memory if an attacker can control hot‑plug operations. The CVSS score is not provided; however, the described denial of service and kernel crash denote high severity.

Generated by OpenCVE AI on September 19, 2026 at 09:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the patch restoring alloc_percpu failure handling.
  • Reboot the system after applying the patch to ensure the changed code is in use.
  • If an immediate patch is unavailable, disable or restrict hot‑plug memory addition features to reduce the chance of triggering the fault.

Generated by OpenCVE AI on September 19, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug We miss a failed allocation check for pgdat->per_cpu_nodestats, which results in a NULL deref when we offset into the per-cpu area. Propagate -ENOMEM up the stack and leave per_cpu_nodestats pointing at boot_nodestats so a later online can retry the allocation. hotadd_init_pgdat() returns NULL on failure, which __try_online_node() already maps to -ENOMEM. On failure nothing needs to be unwound: - the node is never marked online - per_cpu_nodestats is left pointing at boot_nodestats - __add_memory_resource() cleans up pending memblock resources - later online attempts retry the per_cpu_nodestats allocation
Title mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:02.544Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:12.943

Modified: 2026-09-17T17:18:12.943

Link: CVE-2026-93172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:00:13Z

Weaknesses