Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix early boot crash on parameters without '=' separator If hugepages, hugepagesz, or default_hugepagesz are specified on the kernel command line without the '=' separator, early parameter parsing passes NULL to hugetlb_add_param(), which dereferences it in strlen() and can crash the system during early boot. Reject NULL values in hugetlb_add_param() and return -EINVAL instead.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.15, < 6.18.27 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/2774bcf714739cc6bb86f8812167bb9fbda70f6aPatch
- https://git.kernel.org/stable/c/357c6d084b6137ae640209c5bfd01180f985c015Patch
- https://git.kernel.org/stable/c/c45b354911d01565156e38d7f6bc07edb51fc34cPatch
FAQ
What is CVE-2026-46284?
CVE-2026-46284 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix early boot crash on parameters without '=' separator If hugepages, hugepagesz, or default_hugepagesz are specified...
How severe is CVE-2026-46284?
CVE-2026-46284 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-46284?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.