CVE-2026-64167

Summary

In the Linux kernel, the following vulnerability has been resolved:

kho: skip KHO for crash kernel

kho_fill_kimage() unconditionally populates the kimage with KHO metadata for every kexec image type. When the image is a crash kernel, this can be problematic as the crash kernel can run in a small reserved region and the KHO scratch areas can sit outside it. The crash kernel then faults during kho_memory_init() when it tries phys_to_virt() on the KHO FDT address:

Unable to handle kernel paging request at virtual address xxxxxxxx … fdt_offset_ptr+… fdt_check_node_offset_+… fdt_first_property_offset+… fdt_get_property_namelen_+… fdt_getprop+… kho_memory_init+… mm_core_init+… start_kernel+…

kho_locate_mem_hole() already skips KHO logic for KEXEC_TYPE_CRASH images, but kho_fill_kimage() was missing the same guard. As kho_fill_kimage() is the single point that populates image->kho.fdt and image->kho.scratch, fixing it here is sufficient for both arm64 and x86 as the FDT and boot_params path are bailing out when these fields are unset.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxd7255959b69a4e727c61eb04231d11390d4f391e < a6ac6721326a75ff2d14c68db05f93b576d8762faffected
LinuxLinuxd7255959b69a4e727c61eb04231d11390d4f391e < a6715d7ec472a476db17787697a4abda62962284affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.0.11 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References