SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64167

MEDIUM · CVSS 5.5 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of kexec images, specifically when dealing with crash kernels, as the kho_fill_kimage() function improperly populates KHO metadata. This can lead to kernel paging requests that result in faults, potentially causing system instability during crash recovery. System administrators and developers managing Linux environments, particularly those utilizing kexec for crash kernel functionality, should prioritize addressing this issue to ensure system reliability and prevent crashes.

CVE
CVE-2026-64167
Severity
MEDIUM
CVSS
5.5
EPSS
0.10%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: kho: skip KHO for crash kernel kho_fill_kimage() unconditionally populates the kimage with KHO metadata for every kexec image type. When the image is a crash kernel, this can be problematic as the crash kernel can run in a small reserved region and the KHO scratch areas can sit outside it. The crash kernel then faults during kho_memory_init() when it tries phys_to_virt() on the KHO FDT address: Unable to handle kernel paging request at virtual address xxxxxxxx ... fdt_offset_ptr+... fdt_check_node_offset_+... fdt_first_property_offset+... fdt_get_property_namelen_+... fdt_getprop+... kho_memory_init+... mm_core_init+... start_kernel+... kho_locate_mem_hole() already skips KHO logic for KEXEC_TYPE_CRASH images, but kho_fill_kimage() was missing the same guard. As kho_fill_kimage() is the single point that populates image->kho.fdt and image->kho.scratch, fixing it here is sufficient for both arm64 and x86 as the FDT and boot_params path are bailing out when these fields are unset.

Related CVEs

Other vulnerabilities affecting the same vendor(s)