CVE-2026-64244
Low
No strong exploitation signal.
CVSS base
5.5
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
0.1%
1.7th percentile
CISA KEV
Not listed
Weakness / dates
—
Published 2026-07-24 · modified 2026-08-17
CVSS breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | L | Local |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | N | None |
| Integrity | N | None |
| Availability | H | High |
Timeline
- 2026-07-24 — Published (NVD)
- 2026-08-17 — Last modified (NVD)
Description
In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: set mem->altmap after successful device registration If __add_memory_block() fails at xa_store() (under memory pressure for example), device_unregister() is called, which eventually triggers memory_block_release() with mem->altmap still set, causing a WARN_ON(mem->altmap). This was triggered by modifying virtio-mem driver. Fix this by delaying the assignment of mem->altmap until after __add_memory_block() has succeeded.
Affected
References
- https://git.kernel.org/stable/c/059ac6252a63edf1cea79bf30bd860a8c264b62c
- https://git.kernel.org/stable/c/22dc0d042f02ce82aa61422ea5f232628bfd9e9c
- https://git.kernel.org/stable/c/6c25bf4e44a2b6a14332f952bba0974521f5b72d
- https://git.kernel.org/stable/c/802e113cf120df7208e4c7e604950a85e87120a8
- https://git.kernel.org/stable/c/a2b8d7827f48ee54a686cb80e4a1d0ff954ec42a
- https://git.kernel.org/stable/c/bc3dd82a0ffd488bb902f4c69c3d28fd4088d973