CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
In the Linux kernel, the following vulnerability has been resolved:
block: bio-integrity: Fix null-ptr-deref in biointegritymapuser()
pinuserpagesfast() can partially succeed and return the number of pages that were actually pinned. However, the biointegritymapuser() does not handle this partial pinning. This leads to a general protection fault since bvecfrompages() dereferences an unpinned page address, which is 0.
To fix this, add a check to verify that all requested memory is pinned. If partial pinning occurs, unpin the memory and return -EFAULT.
Kernel Oops:
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 RIP: 0010:biointegritymapuser.cold+0x1b0/0x9d6
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 7.0.0-11783-g90957f9314e8-dirtyPatch block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() - Configuration
Update the kernel block bio-integrity code to verify that pin_user_pages_fast fully pins all requested memory; if partial pinning occurs, unpin the memory and return -EFAULT to prevent bvec_from_pages() from dereferencing unpinned pages.
Linux kernel block bio-integrity verify full pinning after pin_user_pages_fast = add check that all requested memory is pinned; handle partial pinning by unpinning and returning -EFAULT
Event History
Frequently Asked Questions
What access does an attacker need to trigger this issue?
The CVSS vector indicates local access with low privileges is required. No user interaction is required.
What is the likely impact if the flaw is triggered?
Partial user-page pinning can cause bio_integrity_map_user() to dereference an unpinned null page address, resulting in a kernel general protection fault or Oops. The stated CVSS impact is high availability impact, with no confidentiality or integrity impact.
How does the fix prevent the crash?
The fix verifies that all requested memory pages were pinned. If pinning is only partial, it unpins the pages that were pinned and returns -EFAULT instead of passing incomplete page information to bvec_from_pages().