CVE-2026-53282
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
x86/kexec: Druk kjump retouradres zelfs voor niet-kjump kexec
De versie van de vagevuurcode die door kexec-tools wordt verzonden, probeert hierboven te kijken
de bovenkant van de stapel om een retouradres te vinden voor een kjump, zelfs in een niet-kjump
kexec. Na de commit in Fixes: het woord boven de stack staat er misschien niet,
wat leidt tot een fout (die in ieder geval nu wordt opgevangen door mijn exception-handling code
in kexec). Die vaste dingen vastleggen voor het eigenlijke kjump-pad, maar niet langer
"onnodig" duwt het ongebruikte retouradres naar de stapel in de niet-kjump
pad. Zet dat *terug* in het niet-kjump pad, om te voorkomen dat het vagevuur
crashen wanneer je er toegang toe probeert te krijgen.
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
x86/kexec: Push kjump return address even for non-kjump kexec
The version of purgatory code shipped by kexec-tools attempts to look above
the top of its stack to find a return address for a kjump, even in a non-kjump
kexec.
After the commit in Fixes: the word above the stack might not be there,
leading to a fault (which is at least now caught by my exception-handling code
in kexec).
That commit fixed things for the actual kjump path, but no longer
"gratuitously" pushes the unused return address to the stack in the non-kjump
path. Put that *back* in the non-kjump path, to prevent purgatory from
crashing when trying to access it.