CVE-2026-72013: riscv: Prevent NULL pointer dereference in machine_kexec_prepare()
In the Linux kernel, the following vulnerability has been resolved:
riscv: Prevent NULL pointer dereference in machinekexecprepare()
A NULL pointer dereference issue is noticed in riscv's machinekexecprepare(), where image->segment[i].buf might be NULL and copied unchecked.
The NULL buf comes from imaaddkexecbuffer(), where kbuf is added by kexecaddbuffer(), but kbuf.buffer is NULL, then it is copied without a check in machinekexecprepare():
kexecfileload -> kimagefileallocinit() -> kimagefilepreparesegments() -> imaaddkexecbuffer() -> kexecaddbuffer() -> machinekexecprepare() -> memcpy()
Address this by adding a check before the data copy attempt.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72013?
The severity of CVE-2026-72013 is rated at risk 18.
How do I fix CVE-2026-72013?
To fix CVE-2026-72013, update the Linux kernel to the latest version that includes the patch for this vulnerability.
What systems are affected by CVE-2026-72013?
CVE-2026-72013 affects systems running the riscv architecture within the Linux kernel.
What is the nature of the vulnerability in CVE-2026-72013?
The nature of the vulnerability in CVE-2026-72013 is a NULL pointer dereference in machine_kexec_prepare() which can lead to potential crashes.
When was CVE-2026-72013 published?
CVE-2026-72013 was published on August 15, 2026.