In the Linux kernel, the following vulnerability has been resolved:
kho: skip KHO for crash kernel
kho_fill_kimage() unconditionally populates the kimage with KHO metadata for every kexec image type. When the image is a crash kernel, this can be problematic as the crash kernel can run in a small reserved region and the KHO scratch areas can sit outside it. The crash kernel then faults during kho_memory_init() when it tries phys_to_virt() on the KHO FDT address:
Unable to handle kernel paging request at virtual address xxxxxxxx ... fdt_offset_ptr+... fdt_check_node_offset_+... fdt_first_property_offset+... fdt_get_property_namelen_+... fdt_getprop+... kho_memory_init+... mm_core_init+... start_kernel+...
kho_locate_mem_hole() already skips KHO logic for KEXEC_TYPE_CRASH images, but kho_fill_kimage() was missing the same guard. As kho_fill_kimage() is the single point that populates image->kho.fdt and image->kho.scratch, fixing it here is sufficient for both arm64 and x86 as the FDT and boot_params path are bailing out when these fields are unset.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-7.0.0-1010-azureUpgrade linux-image-aws-7.0Upgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-raspi-realtimeUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-7.0.0-1014-azureUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1011-oracle-64kUpgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-aws-64k-7.0Upgrade linux-image-oracle-64kUpgrade linux-image-azure-7.0Upgrade linux-image-gcp-7.0Upgrade linux-image-aws-64kUpgrade linux-image-gcpUpgrade linux-image-oracleUpgrade linux-image-awsUpgrade linux-image-raspi-7.0Upgrade linux-image-oracle-64k-7.0Upgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-azureUpgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-nvidia-bosUpgrade linux-image-oracle-7.0Upgrade linux-image-ibmUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-raspiUpgrade linux-image-nvidiaUpgrade linux-image-gcp-64kUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-nvidia-7.0Upgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-ibm-7.0Upgrade linux-image-azure-fdeUpgrade linux-image-azure-fde-7.0Upgrade linux-image-7.0.0-1011-oracleUpgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-nvidia-bos-64k-7.0 | Jul 21, 2026 | Jul 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub