CVE-2026-64244: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: set mem->altmap after successful device registration If __add_memory_block() fails at xa_store() (under memory pressure for example), device_unregister() is called, which eventually triggers memory_block_release() with mem->altmap still set, causing a WARN_ON(mem->altmap). This was triggered by modifying virtio-mem driver. Fix this by delaying the assignment of mem->altmap until after __add_memory_block() has succeeded.

Affected products

  • Linux Linux Kernel: from 6.6, before 6.6.144 (fixed in 6.6.144); from 6.7, before 6.12.95 (fixed in 6.12.95); from 6.13, before 6.18.37 (fixed in 6.18.37); from 6.19, before 7.0.14 (fixed in 7.0.14); from 7.1, before 7.1.2 (fixed in 7.1.2)

Published 2026-07-24. Last modified 2026-08-17.