Linux Kernel Crash Kernel KHO Metadata Vulnerability
CVE-2026-64167

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64167?

A vulnerability in the Linux kernel allows for improper handling of KHO metadata for crash kernel configurations. The function kho_fill_kimage() inadvertently populates the kimage with KHO metadata for all kexec image types, leading to potential faults during the initialization of crash kernels. This is particularly problematic as crash kernels operate within a limited reserved memory space, which may lead to paging errors if the KHO scratch areas extend beyond this space. The issue has been noted for various kernel versions and poses risks to system stability when improper transitions to the crash kernel occur.

Affected Version(s)

Linux d7255959b69a4e727c61eb04231d11390d4f391e

Linux d7255959b69a4e727c61eb04231d11390d4f391e

Linux 6.19

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.