---
id: CVE-2026-46284
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mm/hugetlb: fix early boot crash on parameters without '=' separator

  If hugepages, hugepagesz, or default_hugepagesz are specified on the
  kernel command line without t…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mm/hugetlb: fix early boot crash on parameters without '=' separator

  If hugepages, hugepagesz, or default_hugepagesz are specified on the
  kernel command line without t…
severity: none
published: '2026-06-08'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46284'
references:
  - url: 'https://git.kernel.org/stable/c/2774bcf714739cc6bb86f8812167bb9fbda70f6a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/357c6d084b6137ae640209c5bfd01180f985c015'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c45b354911d01565156e38d7f6bc07edb51fc34c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.0016
epssPercentile: 0.04435
ingestedAt: '2026-07-07T18:42:24.280Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mm/hugetlb: fix early boot crash on parameters without '=' separator

If hugepages, hugepagesz, or default_hugepagesz are specified on the
kernel command line without the '=' separator, early parameter parsing
passes NULL to hugetlb_add_param(), which dereferences it in strlen() and
can crash the system during early boot.

Reject NULL values in hugetlb_add_param() and return -EINVAL instead.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
