CVE-2026-72013: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: riscv: Prevent NULL pointer dereference in machine_kexec_prepare() A NULL pointer dereference issue is noticed in riscv's machine_kexec_prepare(), where image->segment[i].buf might be NULL and copied unchecked. The NULL buf comes from ima_add_kexec_buffer(), where kbuf is added by kexec_add_buffer(), but kbuf.buffer is NULL, then it is copied without a check in machine_kexec_prepare(): kexec_file_load -> kimage_file_alloc_init() -> kimage_file_prepare_segments() -> ima_add_kexec_buffer() -> kexec_add_buffer() -> machine_kexec_prepare() -> memcpy() Address this by adding a check before the data copy attempt.
Affected products
- Linux Linux: from 5.15.47, before 5.15.212 (fixed in 5.15.212); from 5.17.15, before 5.18 (fixed in 5.18); from 5.18.4, before 5.19 (fixed in 5.19); from 5.19, before 6.1.178 (fixed in 6.1.178); from 6.2, before 6.6.145 (fixed in 6.6.145); from 6.7, before 6.12.97 (fixed in 6.12.97); …
Published 2026-08-15. Last modified 2026-08-17.