CVE-2026-64052

Source
https://cve.org/CVERecord?id=CVE-2026-64052
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64052.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64052
Downstream
Published
2026-07-19T15:39:35.223Z
Modified
2026-07-21T03:47:52.147324712Z
Summary
block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
Details

In the Linux kernel, the following vulnerability has been resolved:

block: bio-integrity: Fix null-ptr-deref in biointegritymap_user()

pinuserpagesfast() can partially succeed and return the number of pages that were actually pinned. However, the biointegritymapuser() does not handle this partial pinning. This leads to a general protection fault since bvecfrompages() dereferences an unpinned page address, which is 0.

To fix this, add a check to verify that all requested memory is pinned. If partial pinning occurs, unpin the memory and return -EFAULT.

Kernel Oops:

Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 RIP: 0010:biointegritymap_user.cold+0x1b0/0x9d6

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64052.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
492c5d455969fc2e829f26ed4c83487b068f0dd7
Fixed
77c059f41e9395793917d067476f549a911d77d3
Fixed
76410790f1491c8e06a451045ae223a61c652455
Fixed
8fa244738641d95ea4d70e6f9a62778bba42a5b7
Fixed
8582792cf23b3d94674d4d838f7cde9a28d0fcaf

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64052.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64052.json"