Linux Kernel Crash Kernel KHO Metadata Vulnerability
CVE-2026-64167
Currently unrated
What is CVE-2026-64167?
A vulnerability in the Linux kernel allows for improper handling of KHO metadata for crash kernel configurations. The function kho_fill_kimage() inadvertently populates the kimage with KHO metadata for all kexec image types, leading to potential faults during the initialization of crash kernels. This is particularly problematic as crash kernels operate within a limited reserved memory space, which may lead to paging errors if the KHO scratch areas extend beyond this space. The issue has been noted for various kernel versions and poses risks to system stability when improper transitions to the crash kernel occur.
Affected Version(s)
Linux d7255959b69a4e727c61eb04231d11390d4f391e
Linux d7255959b69a4e727c61eb04231d11390d4f391e
Linux 6.19