CVE-2026-64368

Source
https://cve.org/CVERecord?id=CVE-2026-64368
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64368.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64368
Downstream
Published
2026-07-25T08:50:21.831Z
Modified
2026-07-27T04:03:21.614570730Z
Summary
mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/slab: do not limit zeroing to orig_size when only red zoning is enabled

When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the full object size even if a smaller size is requested, in order to provide krealloc()'s _GFPZERO guarantees.

But if we track the requested size, krealloc() uses that information to do the right thing, so we can zero only the requested size. With red zoning also enabled, any extra size became part of the red zone, so it must not be zeroed and thus we must zero only the requested size.

However the current check is imprecise, and will trigger also when only SLABREDZONE is enabled without SLABSTOREUSER (which enables tracking the requested size). This means enabling red zoning alone can compromise krealloc()'s _GFPZERO contract.

Fix this by using slubdebugorig_size() instead, which is the exact check for whether the requested size is tracked. We don't need to care if red zoning is also enabled or not. Also update and expand the comment accordingly.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64368.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9ce67395f5a0cdec6ce152d26bfda13b98b25c01
Fixed
6256899c3a34674bba6076884aedbba49fc695e4
Fixed
7e706d50fa119eead6376bf0ef973e8d73a96030
Fixed
2382971aaaef5bf85a651234c64906f59580b8be
Fixed
0d18ccef142f04433dfb2a0c120cf223d2b8a42c
Fixed
648927ceb84021a25a0fbd5673740956f318d534

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64368.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64368.json"