CVE-2026-64167
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
kho: skip KHO for crash kernel
kho_fill_kimage() unconditionally populates the kimage with KHO metadata for every kexec image type. When the image is a crash kernel, this can be problematic as the crash kernel can run in a small reserved region and the KHO scratch areas can sit outside it. The crash kernel then faults during kho_memory_init() when it tries phys_to_virt() on the KHO FDT address:
Unable to handle kernel paging request at virtual address xxxxxxxx … fdt_offset_ptr+… fdt_check_node_offset_+… fdt_first_property_offset+… fdt_get_property_namelen_+… fdt_getprop+… kho_memory_init+… mm_core_init+… start_kernel+…
kho_locate_mem_hole() already skips KHO logic for KEXEC_TYPE_CRASH images, but kho_fill_kimage() was missing the same guard. As kho_fill_kimage() is the single point that populates image->kho.fdt and image->kho.scratch, fixing it here is sufficient for both arm64 and x86 as the FDT and boot_params path are bailing out when these fields are unset.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | d7255959b69a4e727c61eb04231d11390d4f391e < a6ac6721326a75ff2d14c68db05f93b576d8762f | affected |
| Linux | Linux | d7255959b69a4e727c61eb04231d11390d4f391e < a6715d7ec472a476db17787697a4abda62962284 | affected |
| Linux | Linux | 6.19 | affected |
| Linux | Linux | 0 < 6.19 | unaffected |
| Linux | Linux | 7.0.11 <= 7.0.* | unaffected |
| Linux | Linux | 7.1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/a6ac6721326a75ff2d14c68db05f93b576d8762f
- https://git.kernel.org/stable/c/a6715d7ec472a476db17787697a4abda62962284
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.