In the Linux kernel, the following vulnerability has been resolved:
kernel/kexec: fix IMA when allocation happens in CMA area
*** Bug description ***
When I tested kexec with the latest kernel, I ran into the following warning:
[ 40.712410] ------------[ cut here ]------------ [ 40.712576] WARNING: CPU: 2 PID: 1562 at kernel/kexec_core.c:1001 kimage_map_segment+0x144/0x198 [...] [ 40.816047] Call trace: [ 40.818498] kimage_map_segment+0x144/0x198 (P) [ 40.823221] ima_kexec_post_load+0x58/0xc0 [ 40.827246] __do_sys_kexec_file_load+0x29c/0x368 [...] [ 40.855423] ---[ end trace 0000000000000000 ]---
*** How to reproduce ***
This bug is only triggered when the kexec target address is allocated in the CMA area. If no CMA area is reserved in the kernel, use the "cma=" option in the kernel command line to reserve one.
*** Root cause *** The commit 07d24902977e ("kexec: enable CMA based contiguous allocation") allocates the kexec target address directly on the CMA area to avoid copying during the jump. In this case, there is no IND_SOURCE for the kexec segment. But the current implementation of kimage_map_segment() assumes that IND_SOURCE pages exist and map them into a contiguous virtual address by vmap().
*** Solution *** If IMA segment is allocated in the CMA area, use its page_address() directly.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.17.0-1015-aws-64kUpgrade linux-image-6.17.0-1018-gcp-64kUpgrade linux-image-generic-64k-6.17Upgrade linux-image-6.17.0-1017-awsUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-1015-azureUpgrade linux-image-6.17.0-29-generic-64kUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-aws-64k-6.17Upgrade linux-image-6.17.0-29-genericUpgrade linux-image-awsUpgrade linux-image-azureUpgrade linux-image-raspiUpgrade linux-image-gcp-64kUpgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-1014-oracle-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-azure-6.17Upgrade linux-image-oracle-6.17Upgrade linux-image-generic-6.17Upgrade linux-image-6.17.0-1023-oemUpgrade linux-image-6.17.0-1014-oracleUpgrade linux-image-oem-24.04cUpgrade linux-image-oem-6.17Upgrade linux-image-realtime-hwe-24.04-edgeUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-6.17.0-1013-realtimeUpgrade linux-image-virtualUpgrade linux-image-realtimeUpgrade linux-image-aws-6.17Upgrade linux-image-oracleUpgrade linux-image-oem-24.04aUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-virtual-6.17Upgrade linux-image-6.17.0-1015-awsUpgrade linux-image-gcp-6.17Upgrade linux-image-6.17.0-1017-aws-64kUpgrade linux-image-generic-64kUpgrade linux-image-oem-24.04Upgrade linux-image-aws-64kUpgrade linux-image-6.17.0-1017-raspiUpgrade linux-image-oem-24.04dUpgrade linux-image-oem-24.04bUpgrade linux-image-genericUpgrade linux-image-6.17.0-1018-gcpUpgrade linux-image-realtime-6.17Upgrade linux-image-oracle-64k | May 25, 2026 | May 19, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub