PT-2026-64638 · Linux+1 · Linux Kernel+1

CVE-2026-64417

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference exists in the debugfs implementation of the memory management shrinker. The function shrinker debugfs add() unconditionally creates count and scan debugfs files, assuming that every shrinker implements both count objects() and scan objects() callbacks. If a shrinker omits one of these callbacks, such as the xen-backend shrinker which leaves scan objects() as NULL, writing to the corresponding debugfs file triggers a call through a NULL function pointer, resulting in a kernel panic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64417
ECHO-97F4-453C-D191
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu